Description
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1751
http://www.openwall.com/lists/oss-security/2020/02/12/3
Related Vulnerabilities
CVE-2021-42228 Vulnerability in npm package kindeditor
CVE-2023-20866 Vulnerability in maven package org.springframework.session:spring-session-core
CVE-2015-7520 Vulnerability in maven package org.apache.wicket:wicket-core
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-spi
CVE-2018-1000143 Vulnerability in maven package org.jenkins-ci.plugins:ghprb