Jenkins Matrix Authorization Strategy vulnerabilities
3 known vulnerabilities affecting jenkins/matrix_authorization_strategy.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-42521P3MEDIUMCVSS 6.5≥ 2.1, < 3.2.10v2.02026-04-29
CVE-2026-42521 [MEDIUM] CWE-502 CVE-2026-42521: Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes param
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which ma
nvd
CVE-2021-21623P3MEDIUMCVSS 6.5≤ 2.6.52021-03-18
CVE-2021-21623 [MEDIUM] CWE-863 CVE-2021-21623: An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allo
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
nvd
CVE-2020-2226P4MEDIUMCVSS 5.4≤ 2.6.12020-07-15
CVE-2020-2226 [MEDIUM] CWE-79 CVE-2020-2226: Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in t
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
nvd