{ "id": "CVE-2023-49655", "sourceIdentifier": "jenkinsci-cert@googlegroups.com", "published": "2023-11-29T14:15:07.617", "lastModified": "2023-11-29T15:15:09.343", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system." } ], "metrics": {}, "references": [ { "url": "http://www.openwall.com/lists/oss-security/2023/11/29/1", "source": "jenkinsci-cert@googlegroups.com" }, { "url": "https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3193", "source": "jenkinsci-cert@googlegroups.com" } ] }