Description
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/09/01/3
https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1829
Related Vulnerabilities
CVE-2020-36518 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-30528 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth
CVE-2018-25050 Vulnerability in npm package chosen-js
CVE-2019-15608 Vulnerability in npm package yarn
CVE-2021-23383 Vulnerability in maven package org.webjars.npm:handlebars