GHSA-cjgm-9vc9-56mx
GitHub Security Advisory
Path traversal vulnerability in Jenkins Matrix Project Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects submitted through the `config.xml` REST API endpoint.
This allows attackers with Item/Configure permission to create or replace any `config.xml` file on the Jenkins controller file system with content not controllable by the attackers.
Matrix Project Plugin 822.824.v14451b_c0fd42 sanitizes user-defined axis names of Multi-configuration project.
Affected Packages
Maven
org.jenkins-ci.plugins:matrix-project
Affected versions:
0
(fixed in 822.824.v14451b)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.