Description
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/09/01/3
https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1831
Related Vulnerabilities
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2021-40146 Vulnerability in maven package org.apache.any23:apache-any23-core
CVE-2013-7381 Vulnerability in npm package libnotify
CVE-2020-7723 Vulnerability in npm package promisehelpers
CVE-2022-46363 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http