Description
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Remediation
References
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-637
Related Vulnerabilities
CVE-2009-0781 Vulnerability in maven package tomcat:catalina
CVE-2023-45137 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-24431 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2017-15691 Vulnerability in maven package org.apache.uima:uimaj-examples
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee8:jetty-ee8-servlets