CVE-2023-49654

CRITICAL

Jenkins MATLAB Plugin < 2.11.1 - Unauthenticated XML File Parsing via Missing Permission Checks

Title source: llm
STIX 2.1

Description

Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 25.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (2)
jenkins/matlab < 2.11.1
org.jenkins-ci.plugins/matlab 0 - 2.11.1Maven
Published Nov 29, 2023
Tracked Since Feb 18, 2026