Description
Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2805
Related Vulnerabilities
CVE-2022-24948 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2022-46870 Vulnerability in maven package org.apache.zeppelin:zeppelin-web
CVE-2023-44487 Vulnerability in maven package io.helidon.http:helidon-http-http2
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-core
CVE-2017-15703 Vulnerability in maven package org.apache.nifi:nifi-file-authorizer