Description
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2926
Related Vulnerabilities
CVE-2019-1003070 Vulnerability in maven package org.jenkins-ci.plugins:veracode-scanner
CVE-2018-1999028 Vulnerability in maven package org.jenkins-ci.plugins:accurev
CVE-2018-11087 Vulnerability in maven package org.springframework.amqp:spring-amqp
CVE-2022-45395 Vulnerability in maven package com.thalesgroup.jenkins-ci.plugins:cccc
CVE-2020-17530 Vulnerability in maven package org.apache.struts:struts2-core