CVE-2020-2172: Improper Restriction of Recursive Entity References in DTDs (XML Entity Expansion)
Jenkins Code Coverage API Plugin does not configure its XML parser to prevent XML external entity (XXE) attacks.
References
Detect and mitigate CVE-2020-2172 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →