Description
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Remediation
References
https://jenkins.io/security/advisory/2018-02-05/
Related Vulnerabilities
CVE-2019-16303 Vulnerability in npm package generator-jhipster-kotlin
CVE-2023-30514 Vulnerability in maven package org.jenkins-ci.plugins:azure-keyvault
CVE-2017-7957 Vulnerability in maven package org.jvnet.hudson:xstream
CVE-2022-36886 Vulnerability in maven package org.jenkins-ci.plugins:external-monitor-job
CVE-2014-9635 Vulnerability in maven package org.jenkins-ci.main:jenkins-core