Description
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Remediation
References
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-637
Related Vulnerabilities
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2016-2402 Vulnerability in maven package com.squareup.okhttp:okhttp
CVE-2010-2275 Vulnerability in npm package dojo
CVE-2019-9658 Vulnerability in maven package com.puppycrawl.tools:checkstyle
CVE-2011-1475 Vulnerability in maven package org.apache.tomcat:tomcat-catalina