Description
Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2925
Related Vulnerabilities
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_sjs1_2.13
CVE-2014-3501 Vulnerability in npm package cordova-android
CVE-2015-5174 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2019-0193 Vulnerability in maven package org.apache.solr:solr-dataimporthandler