QID 996881
Date Published: 2024-01-31
QID 996881: Java (Maven) Security Update for org.jenkins-ci.plugins:matrix-project (GHSA-cjgm-9vc9-56mx)
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cjgm-9vc9-56mx for updates and patch information.
Vendor References
- GHSA-cjgm-9vc9-56mx -
github.com/advisories/GHSA-cjgm-9vc9-56mx
CVEs related to QID 996881
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cjgm-9vc9-56mx | org.jenkins-ci.plugins:matrix-project |
|