Description
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/11/29/1
https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3193
Related Vulnerabilities
CVE-2020-2298 Vulnerability in maven package org.jenkins-ci.plugins:nerrvana-plugin
CVE-2022-37023 Vulnerability in maven package org.apache.geode:geode-core
CVE-2018-1273 Vulnerability in maven package org.springframework.data:spring-data-commons
CVE-2020-2126 Vulnerability in maven package com.dubture.jenkins:digitalocean-plugin