CVE-2024-23900
MEDIUMDescription
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
Is your site exposed to CVE-2024-23900?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| jenkins | matrix_project |
References
Frequently Asked Questions
What is CVE-2024-23900? +
How severe is CVE-2024-23900? +
What products are affected by CVE-2024-23900? +
How do I check if I'm vulnerable to CVE-2024-23900? +
Related Vulnerabilities
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission …
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, …
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces …
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, …
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, …
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of …