Description
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Remediation
References
http://www.securityfocus.com/bid/102844
https://jenkins.io/security/advisory/2018-01-22/
Related Vulnerabilities
CVE-2021-23543 Vulnerability in npm package realms-shim
CVE-2018-16487 Vulnerability in npm package lodash.merge
CVE-2018-1000136 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-1784 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent
CVE-2022-29258 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui