<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Liquibase</title>
  <link>https://cvedaily.com/pages/tags/liquibase.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/liquibase.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Liquibase</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-0839 – Improper Restriction of XML External Entity Reference in GitHub repository liqui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0839</guid>
    <pubDate>Fri, 04 Mar 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-0839</strong></p>
  <p>Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-2285 – A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2285</guid>
    <pubDate>Wed, 23 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-2285</strong></p>
  <p>A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2284 – Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML par...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2284</guid>
    <pubDate>Wed, 23 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2284</strong></p>
  <p>Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-2283 – Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2283</guid>
    <pubDate>Wed, 23 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-2283</strong></p>
  <p>Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000146 – An arbitrary code execution vulnerability exists in Liquibase Runner Plugin vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000146</guid>
    <pubDate>Thu, 05 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000146</strong></p>
  <p>An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000146">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
