Description
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2937
http://www.openwall.com/lists/oss-security/2022/11/15/4
Related Vulnerabilities
CVE-2016-10549 Vulnerability in npm package sails
CVE-2019-16303 Vulnerability in npm package generator-jhipster-kotlin
CVE-2017-9787 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-42767 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2023-40312 Vulnerability in maven package org.opennms:opennms-webapp