Matrix Project

Vendor:

First CVE: Mar 8, 2019 · Active for 7 years

5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Matrix Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2019
7 years ago
Most Recent CVE
Jan 24, 2024
915 days ago

CVE Severity & Scoring

Matrix Project5 CVEs
All CVEs352,785 CVEs
MediumCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low5 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS)
Jan 12, 20225.464NONO
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Con
Mar 8, 20199.931NONO
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site
Jul 15, 20205.416NONO
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site
Jul 15, 20205.416NONO
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permi
Jan 24, 20244.314NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Matrix Project

Top CWEs

Versions

No cataloged versions.