Related Vulnerabilities: CVE-2022-28155  

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Severity High

Remote Yes

Type Xml external entity injection

Description

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

AVG-2678 jenkins 0.0.0-1 High Not affected

https://www.openwall.com/lists/oss-security/2022/03/29/1
https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-1897