Path traversal in Matrix Project - CVE-2024-23900

 

Path traversal in Matrix Project - CVE-2024-23900

Published: January 25, 2024


Vulnerability identifier: #VU85792
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23900
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to the affected plugin does not sanitize user-defined axis names of multi-configuration projects submitted through the config.xml REST API endpoint. A remote user can create or replace any config.xml file on the Jenkins controller file system with content not controllable by the attackers.


Affected software

Matrix Project
OpenShift Developer Tools and Services
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-23900

Install update from vendor's website.

Matrix Project - update to 822.824.v14451b_c0fd42
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8

External References

Related Security Bulletins