Description
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2937
Related Vulnerabilities
CVE-2020-2131 Vulnerability in maven package org.jenkins-ci.plugins:harvest
CVE-2020-7699 Vulnerability in npm package express-fileupload
CVE-2019-5457 Vulnerability in npm package min-http-server
CVE-2020-2297 Vulnerability in maven package com.hoiio.jenkins:sms
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat:tomcat