CVE Vulnerabilities

CVE-2024-23900

Published: Jan 24, 2024 | Modified: Jun 16, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

Affected Software

NameVendorStart VersionEnd Version
Matrix_projectJenkins*822.v01b_8c85d16d2 (including)
OCP-Tools-4.12-RHEL-8RedHatjenkins-0:2.440.3.1716445200-3.el8*
OCP-Tools-4.12-RHEL-8RedHatjenkins-2-plugins-0:4.12.1716445211-1.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-0:2.440.3.1716445150-3.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-2-plugins-0:4.13.1716445207-1.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-0:2.440.3.1716387933-3.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-2-plugins-0:4.14.1716388016-1.el8*
OCP-Tools-4.15-RHEL-8RedHatjenkins-0:2.440.3.1718879390-3.el8*
OCP-Tools-4.15-RHEL-8RedHatjenkins-2-plugins-0:4.15.1718879538-1.el8*

References