Lucene search

K
cvelistJenkinsCVELIST:CVE-2024-23900
HistoryJan 24, 2024 - 5:52 p.m.

CVE-2024-23900

2024-01-2417:52:24
jenkins
www.cve.org
jenkins
matrix project plugin
config.xml files
multi-configuration projects
security vulnerability
cve-2024-23900

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.5%

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

CNA Affected

[
  {
    "vendor": "Jenkins Project",
    "product": "Jenkins Matrix Project Plugin",
    "versions": [
      {
        "version": "0",
        "versionType": "maven",
        "lessThanOrEqual": "822.v01b_8c85d16d2",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.5%