Description
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
Remediation
References
https://github.com/advisories/GHSA-j3h2-8mf8-j5r2
https://security.snyk.io/vuln/SNYK-JAVA-ORGJVNETHUDSONMAIN-31221
https://wiki.eclipse.org/Hudson-ci/alerts/CVE-2015-8031
Related Vulnerabilities
CVE-2022-36890 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework
CVE-2023-31718 Vulnerability in npm package @frangoteam/fuxa
CVE-2020-7639 Vulnerability in npm package eivindfjeldstad-dot
CVE-2021-23396 Vulnerability in npm package lutils
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui