cbcvebase.
CVE-2023-49654
published 2023-11-29

CVE-2023-49654: Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.

Affected

5 ranges
VendorProductVersion rangeFixed in
jenkinsgoogle_compute_engine_plugin
jenkinsjira_plugin
jenkinsmatlab< 2.11.12.11.1
jenkinsmatlab_plugin
jenkins_projectjenkins_matlab_plugin<= 2.11.0