CVE-2024-23900
Jenkins Matrix Project ≤ 822.v01b_8c85d16d2
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSummary
CVE-2024-23900 is a medium-severity an unspecified weakness vulnerability in Jenkins Matrix Project. Its CVSS base score is 4.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 49th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-0334
Vulnerability Data
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the…
more
attackers.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
CVE-2024-23900 enables limited arbitrary config.xml file writes facilitating T1565.001 (stored data manipulation), T1053/T1059 (modifying jobs for scheduled execution/commands), T1562.001 (impair defenses via job corruption); associated advisories detail file reads (T1005/T1081/T1552.001) enabling credential access and follow-on RCE.
MITRE ATLAS TechniquesAI
MITRE ATLAS techniques
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.