Description
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/12/03/2
https://www.jenkins.io/security/advisory/2020-12-03/#SECURITY-2146
Related Vulnerabilities
CVE-2023-41080 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2023-37955 Vulnerability in maven package org.jenkins-ci.plugins:test-results-aggregator
CVE-2019-15955 Vulnerability in npm package total.js
CVE-2019-16566 Vulnerability in maven package org.jenkins-ci.plugins:teamconcert
CVE-2023-37944 Vulnerability in maven package org.datadog.jenkins.plugins:datadog