CVE-2024-23900 is a medium-severity vulnerability affecting Jenkins Matrix Project Plugin versions 822.v01b_8c85d16d2 and earlier. It allows authenticated attackers with Item/Configure permission to overwrite arbitrary config.xml files on the Jenkins controller filesystem by exploiting unsanitized user-defined axis names in multi-configuration projects. The vulnerability has a CVSS score of 4.3, indicating low impact with no confidentiality or availability compromise, but potential integrity loss. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, and it has received minimal community discussion and media coverage, with its EPSS and FAUCET scores suggesting a very low likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 822.v01b_8c85d16d2CPE matchmatch criteria | cpe:2.3:a:jenkins:matrix_project:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.