Description
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
Remediation
References
https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1698
Related Vulnerabilities
CVE-2023-37277 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2014-7809 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-2166 Vulnerability in maven package de.taimos:pipeline-aws
CVE-2019-10293 Vulnerability in maven package org.jenkins-ci.plugins:kmap-jenkins
CVE-2023-45136 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates