Matrix Project
Vendor:
First CVE: Mar 8, 2019 · Active for 7 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Matrix Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2019
7 years ago
Most Recent CVE
Jan 24, 2024
915 days ago
CVE Severity & Scoring
Matrix Project5 CVEs
80%
20%
All CVEs352,785 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low5 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-20615MEDIUM Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) | Jan 12, 2022 | 5.4 | 64 | NO | NO |
CVE-2019-1003031CRITICAL A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Con | Mar 8, 2019 | 9.9 | 31 | NO | NO |
CVE-2020-2225MEDIUM Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site | Jul 15, 2020 | 5.4 | 16 | NO | NO |
CVE-2020-2224MEDIUM Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site | Jul 15, 2020 | 5.4 | 16 | NO | NO |
CVE-2024-23900MEDIUM Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permi | Jan 24, 2024 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Matrix Project
Top CWEs
Versions
No cataloged versions.