cbcvebase.
CVE-2024-23900
published 2024-01-24

CVE-2024-23900: Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.69%
50.9th percentile
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsgit_server_plugin——
jenkinsgitlab_branch_source_plugin——
jenkinsjenkins_core——
jenkinsjenkins_lts——
jenkinsjenkins_uses_the_strict_crumb_issuer_plugin——
jenkinsjenkins_weekly——
jenkinslog_command_plugin——
jenkinsmatrix_project<= 822.v01b_8c85d16d2—
jenkinsmatrix_project_plugin——
jenkinsqualys_policy_compliance_scanning_connector_plugin——
jenkinsred_hat_dependency_analytics_plugin——
jenkins_projectjenkins_matrix_project_plugin<= 822.v01b_8c85d16d2—

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.