Description
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
Remediation
References
https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1698
Related Vulnerabilities
CVE-2023-48293 Vulnerability in maven package org.xwiki.contrib:xwiki-application-admintools
CVE-2016-8746 Vulnerability in maven package org.apache.ranger:ranger
CVE-2023-51656 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2022-34811 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-web-api