Vulnerabilities > Mojohaus

DATE CVE VULNERABILITY TITLE RISK
2020-01-06 CVE-2019-20343 Code Injection vulnerability in Mojohaus Exec Maven 1.1.1
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).
network
low complexity
mojohaus CWE-94
critical
9.8