Description
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Remediation
References
Related Vulnerabilities
Joomla! Core 2.5.x Information Disclosure (2.5.0 - 2.5.8)
WordPress Plugin ICustomizer Cross-Site Scripting (1.4.13)
MySQL CVE-2020-2780 Vulnerability (CVE-2020-2780)
Moodle Improper Input Validation Vulnerability (CVE-2019-10134)
Atlassian Jira Incorrect Behavior Order: Validate Before Canonicalize Vulnerability (CVE-2022-26136)