CVE-2024-23900: Path Traversal
Jenkins Matrix Project Plugin 822.v01b8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects submitted through the config.xml REST API endpoint.
This allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system with content not controllable by the attackers.
Matrix Project Plugin 822.824.v14451bc0fd42 sanitizes user-defined axis names of Multi-configuration project.
Other sources
Jenkins Matrix Project Plugin 822.v01b8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.plugins:matrix-projectto a version that resolves this vulnerability.Fixed in 822.824.v14451b - Upgrade
Upgrade
redhat/matrix-projectto a version that resolves this vulnerability.Fixed in 822.824. - Upgrade
Upgrade
Jenkins Matrix Project Pluginto a version that resolves this vulnerability.Fixed in 822.824.v14451b_c0fd42 - Compensating control
Restrict Item/Configure permission in Jenkins so untrusted users cannot access the Matrix Project Plugin config.xml REST API endpoint.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23900?
CVE-2024-23900 has been classified with a high severity level due to its potential to allow unauthorized access to modify Jenkins configuration.
How do I fix CVE-2024-23900?
To fix CVE-2024-23900, upgrade the Jenkins Matrix Project Plugin to version 822.824.v14451b or later.
What versions are affected by CVE-2024-23900?
CVE-2024-23900 affects Jenkins Matrix Project Plugin versions up to 822.v01b_8c85d16d2.
Who is impacted by CVE-2024-23900?
Users or systems running vulnerable versions of the Jenkins Matrix Project Plugin with Item/Configure permission are at risk due to CVE-2024-23900.
Can CVE-2024-23900 be exploited remotely?
Yes, CVE-2024-23900 can potentially be exploited remotely if an attacker has the requisite permissions in Jenkins.