Path traversal in MathWorks Polyspace - CVE-2023-37960
Published: July 17, 2023 / Updated: March 13, 2024
MathWorks Polyspace
Jenkins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in Polyspace Notification post-build step. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.