CVE-2023-49656XML External Entity (XXE) Injection in Jenkins Matlab

Severity
9.8CRITICALNVD
EPSS
0.0%
top 85.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29

Description

Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Jenkins MATLAB Plugin XML External Entity vulnerability2023-11-29
GHSA
Jenkins MATLAB Plugin XML External Entity vulnerability2023-11-29
CVEList
CVE-2023-49656: Jenkins MATLAB Plugin 22023-11-29

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-11-292023-11-29
CVE-2023-49656 — XML External Entity (XXE) Injection | cvebase