Description
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1752
http://www.openwall.com/lists/oss-security/2020/02/12/3
Related Vulnerabilities
CVE-2022-4135 Vulnerability in npm package electron
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2016-3101 Vulnerability in maven package org.jenkins-ci.plugins:extra-columns
CVE-2023-3691 Vulnerability in maven package org.webjars:layui
CVE-2022-36913 Vulnerability in maven package org.jenkins-ci.plugins:openstack-heat