Missing Permission Checks in Jenkins MATLAB Plugin by Jenkins
CVE-2023-49654
9.8CRITICAL
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 29 November 2023
What is CVE-2023-49654?
The Jenkins MATLAB Plugin, version 2.11.0 and earlier, is affected by a security flaw that allows unauthorized attackers to exploit missing permission checks. This vulnerability enables attackers to instruct Jenkins to parse an XML file directly from the Jenkins controller's file system, potentially leading to unauthorized access or disclosure of sensitive information. Proper safeguards are necessary to mitigate these risks and protect user data from potential exploitation.
Affected Version(s)
Jenkins MATLAB Plugin 0 <= 2.11.0