Path traversal vulnerability in Jenkins Matrix Project Plugin
Moderate severity
GitHub Reviewed
Published
Jan 24, 2024
to the GitHub Advisory Database
•
Updated Jan 31, 2024
Package
Affected versions
< 822.824.v14451b
Patched versions
822.824.v14451b
Description
Published by the National Vulnerability Database
Jan 24, 2024
Published to the GitHub Advisory Database
Jan 24, 2024
Reviewed
Jan 24, 2024
Last updated
Jan 31, 2024
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects submitted through the
config.xml
REST API endpoint.This allows attackers with Item/Configure permission to create or replace any
config.xml
file on the Jenkins controller file system with content not controllable by the attackers.Matrix Project Plugin 822.824.v14451b_c0fd42 sanitizes user-defined axis names of Multi-configuration project.
References