Missing Permission Checks in Jenkins MATLAB Plugin by Jenkins
CVE-2023-49654
9.8CRITICAL
Summary
The Jenkins MATLAB Plugin, version 2.11.0 and earlier, is affected by a security flaw that allows unauthorized attackers to exploit missing permission checks. This vulnerability enables attackers to instruct Jenkins to parse an XML file directly from the Jenkins controller's file system, potentially leading to unauthorized access or disclosure of sensitive information. Proper safeguards are necessary to mitigate these risks and protect user data from potential exploitation.
Affected Version(s)
Jenkins MATLAB Plugin 0 <= 2.11.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved