Back to search
CVE-2024-23900
Published: Jan 24, 2024
Modified: Jun 16, 2025
PUBLISHED
Description
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins Matrix Project Plugin | affected 0 - <= 822.v01b_8c85d16d2 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now