org.jenkins-ci.plugins:matrix-auth
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:matrix-authpage 1 of 1
- CVE-2020-2226MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.6.22020-07-15
vulnerable: 1.0 ... 2.6.1 (28 versions)
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
- CVE-2021-21623MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.6.62021-03-18
vulnerable: 1.0 ... 2.6.5 (33 versions)
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
- CVE-2026-42521MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.2.102026-04-29
vulnerable: 2.0 ... 3.2.9 (49 versions)
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that…
Check whether org.jenkins-ci.plugins:matrix-auth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:matrix-auth CVEs against the assets you own.
Start Free Scan →