First published: Wed Nov 29 2023(Updated: )
A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Matlab | <2.11.1 | |
maven/org.jenkins-ci.plugins:matlab | <2.11.1 | 2.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49655 is a cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier.
CVE-2023-49655 has a severity score of 7.1 (high).
Jenkins MATLAB Plugin determines the location of a MATLAB installation by parsing an XML file in a user-specified directory on the Jenkins controller.
MATLAB Plugin 2.11.0 and earlier are affected by CVE-2023-49655.
To fix CVE-2023-49655, upgrade to MATLAB Plugin version 2.11.1 or higher.