Jenkins Matrix Project Plugin Vulnerability Exposes Config Files to Unauthorized Changes
CVE-2024-23900
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 24 January 2024
What is CVE-2024-23900?
The Jenkins Matrix Project Plugin prior to version 822.v01b_8c85d16d2 is vulnerable due to improper sanitization of user-defined axis names within multi-configuration projects. Consequently, attackers with Item/Configure permissions can exploit this flaw to create or modify config.xml files on the Jenkins controller file system. This misconfiguration allows potentially malicious content that is not directly controlled by the attackers to be introduced, impacting the integrity of the Jenkins server configurations.
Affected Version(s)
Jenkins Matrix Project Plugin 0 <= 822.v01b_8c85d16d2