<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Liquibase (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/liquibase.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/liquibase-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Liquibase (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-0839 – Improper Restriction of XML External Entity Reference in GitHub repository liqui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0839</guid>
    <pubDate>Fri, 04 Mar 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-0839</strong></p>
  <p>Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2284 – Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML par...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2284</guid>
    <pubDate>Wed, 23 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2284</strong></p>
  <p>Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000146 – An arbitrary code execution vulnerability exists in Liquibase Runner Plugin vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000146</guid>
    <pubDate>Thu, 05 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000146</strong></p>
  <p>An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000146">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
