Cyber Resilience

CVE-2024-23900

Jenkins Matrix Project ≤ 822.v01b_8c85d16d2

Published
24 January 2024
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score 0.0069 49th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2024-23900 is a medium-severity an unspecified weakness vulnerability in Jenkins Matrix Project. Its CVSS base score is 4.3 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 49th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the…

more

attackers.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
T1053 Scheduled Task/Job Execution
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
T1059 Command and Scripting Interpreter Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
T1685 Disable or Modify Tools Defense Impairment
Adversaries may disable, degrade, or tamper with security tools or applications (e.
T1565.001 Stored Data Manipulation Impact
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
Why these techniques?

CVE-2024-23900 enables limited arbitrary config.xml file writes facilitating T1565.001 (stored data manipulation), T1053/T1059 (modifying jobs for scheduled execution/commands), T1562.001 (impair defenses via job corruption); associated advisories detail file reads (T1005/T1081/T1552.001) enabling credential access and follow-on RCE.

MITRE ATLAS TechniquesAI

MITRE ATLAS techniques

AML.T0010: AI Supply Chain CompromiseAML.T0024: Exfiltration via AI Inference APIAML.T0048: External Harms

CVEs Like This One

CVE-2024-23899Same vendor: Jenkins
CVE-2025-64134Same vendor: Jenkins
CVE-2024-23904Same vendor: Jenkins
CVE-2026-33003Same vendor: Jenkins
CVE-2026-48920Same vendor: Jenkins
CVE-2025-64147Same vendor: Jenkins
CVE-2026-57302Same vendor: Jenkins
CVE-2024-28154Same vendor: Jenkins
CVE-2023-46653Same vendor: Jenkins
CVE-2025-67637Same vendor: Jenkins

Affected Assets

jenkins
matrix project
≤ 822.v01b_8c85d16d2

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References