Description
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2928
Related Vulnerabilities
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_3
CVE-2016-0956 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2023-31098 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity