Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
https://github.com/Live-Hack-CVE/CVE-2022-45386
https://github.com/advisories/GHSA-4598-wcg8-x56g
https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-766