Description
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2928
Related Vulnerabilities
CVE-2023-29515 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui
CVE-2018-1999035 Vulnerability in maven package com.inedo.buildmaster:inedo-buildmaster
CVE-2022-34779 Vulnerability in maven package com.xebialabs.ci:xlrelease-plugin
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2019-10080 Vulnerability in maven package org.apache.nifi:nifi-security-utils