Description
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Remediation
References
http://www.securityfocus.com/bid/102844
https://jenkins.io/security/advisory/2018-01-22/
Related Vulnerabilities
CVE-2019-16571 Vulnerability in maven package org.jenkins-ci.plugins:rapiddeploy-jenkins
CVE-2017-2610 Vulnerability in maven package org.jenkins-ci.main:jenkins-war
CVE-2022-29257 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-7774 Vulnerability in maven package org.webjars.npm:y18n