Loading HuntDB...

GHSA-cjgm-9vc9-56mx

GitHub Security Advisory

Path traversal vulnerability in Jenkins Matrix Project Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects submitted through the `config.xml` REST API endpoint.

This allows attackers with Item/Configure permission to create or replace any `config.xml` file on the Jenkins controller file system with content not controllable by the attackers.

Matrix Project Plugin 822.824.v14451b_c0fd42 sanitizes user-defined axis names of Multi-configuration project.

Affected Packages

Maven org.jenkins-ci.plugins:matrix-project
Affected versions: 0 (fixed in 822.824.v14451b)

Related CVEs

Key Information

GHSA ID
GHSA-cjgm-9vc9-56mx
Published
January 24, 2024 6:31 PM
Last Modified
January 31, 2024 8:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:matrix-project
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.