Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3193 | vendor advisory |
http://www.openwall.com/lists/oss-security/2023/11/29/1 | mailing list |