cbcvebase.
CVE-2024-23900
published 2024-01-24

CVE-2024-23900: Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsgit_server_plugin
jenkinsgitlab_branch_source_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_uses_the_strict_crumb_issuer_plugin
jenkinsjenkins_weekly
jenkinslog_command_plugin
jenkinsmatrix_project<= 822.v01b_8c85d16d2
jenkinsmatrix_project_plugin
jenkinsqualys_policy_compliance_scanning_connector_plugin
jenkinsred_hat_dependency_analytics_plugin
jenkins_projectjenkins_matrix_project_plugin<= 822.v01b_8c85d16d2