First published: Wed Nov 29 2023(Updated: )
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Matlab | <2.11.1 | |
maven/org.jenkins-ci.plugins:matlab | <2.11.1 | 2.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49656 is a vulnerability in the Jenkins MATLAB Plugin that allows for XML external entity (XXE) attacks.
The severity of CVE-2023-49656 is not specified in the available information.
CVE-2023-49656 affects Jenkins MATLAB Plugin versions 2.11.0 and earlier.
To fix CVE-2023-49656, upgrade Jenkins MATLAB Plugin to version 2.11.1 or higher.
Additional information about CVE-2023-49656 can be found at the following references: [1] [2] [3].