CVE detail
CVE-2024-23900 — CVE-2024-23900
Published 2024-01-24 · Modified 2026-06-17 · Vendor jenkins · Product matrix_project · Source nvd
MEDIUM
severity
CVSS-derived band
0.0069
EPSS probability
exploitation probability, 30d
49.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References