First published: Wed Jan 24 2024(Updated: )
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects submitted through the `config.xml` REST API endpoint. This allows attackers with Item/Configure permission to create or replace any `config.xml` file on the Jenkins controller file system with content not controllable by the attackers. Matrix Project Plugin 822.824.v14451b_c0fd42 sanitizes user-defined axis names of Multi-configuration project.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:matrix-project | <822.824.v14451b | 822.824.v14451b |
Jenkins Matrix Project Jenkins | <=822.v01b_8c85d16d2 | |
redhat/matrix-project | <822.824. | 822.824. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.