CVE Vulnerabilities

CVE-2024-23900

Published: Jan 24, 2024 | Modified: Jan 31, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Ubuntu

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.

Affected Software

Name Vendor Start Version End Version
Matrix_project Jenkins * 822.v01b_8c85d16d2 (including)
OCP-Tools-4.12-RHEL-8 RedHat jenkins-0:2.440.3.1716445200-3.el8 *
OCP-Tools-4.12-RHEL-8 RedHat jenkins-2-plugins-0:4.12.1716445211-1.el8 *
OCP-Tools-4.13-RHEL-8 RedHat jenkins-0:2.440.3.1716445150-3.el8 *
OCP-Tools-4.13-RHEL-8 RedHat jenkins-2-plugins-0:4.13.1716445207-1.el8 *
OCP-Tools-4.14-RHEL-8 RedHat jenkins-0:2.440.3.1716387933-3.el8 *
OCP-Tools-4.14-RHEL-8 RedHat jenkins-2-plugins-0:4.14.1716388016-1.el8 *
OCP-Tools-4.15-RHEL-8 RedHat jenkins-0:2.440.3.1718879390-3.el8 *
OCP-Tools-4.15-RHEL-8 RedHat jenkins-2-plugins-0:4.15.1718879538-1.el8 *

References