Description
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Remediation
References
https://jenkins.io/security/advisory/2018-01-22/
http://www.securityfocus.com/bid/102844
Related Vulnerabilities
CVE-2023-34036 Vulnerability in maven package org.springframework.hateoas:spring-hateoas
CVE-2018-7408 Vulnerability in maven package org.webjars.npm:npm
CVE-2023-38687 Vulnerability in npm package svelecte
CVE-2022-41232 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2022-39248 Vulnerability in maven package org.matrix.android:matrix-android-sdk2