Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. Reference: http://www.openwall.com/lists/oss-security/2020/02/12/3
External References: https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1752
I don't think, this affects the package https://apps.fedoraproject.org/packages/nunit or https://apps.fedoraproject.org/packages/nunit2 If I understand correctly, this security issue is in a plugin of Jenkins, which includes NUnit in Jenkins. I have never heard about NUnit Plugin 0.25 before. https://plugins.jenkins.io/nunit/ "This plugin makes it possible to import NUnit reports from each build into Jenkins so they are displayed with a trend graph and details about which tests that failed."