Description
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
Remediation
References
http://www.securityfocus.com/bid/102844
https://jenkins.io/security/advisory/2018-01-22/
Related Vulnerabilities
CVE-2020-6451 Vulnerability in npm package electron
CVE-2021-46037 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2020-7661 Vulnerability in maven package org.webjars.npm:url-regex
CVE-2022-40150 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2016-10586 Vulnerability in npm package macaca-chromedriver