openwall.com
http://www.openwall.com/lists/oss-security/2023/09/20/5 CVE-2023-43497
HIGH
Jenkins temporary uploaded file created with insecure permissions
Record summary
CVE-2023-43497 has a selected CVSS score of 8.1 (high).
Description
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 24, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | 2.424 to < * | unaffected |
| 2.414.2 to < 2.414.* | unaffected | ||
jenkinsBrowse jenkins / jenkinsDefault status: unknown | CVE List | Before 2.423 | affected |
| Before lts_2.414.1 | affected | ||
org.jenkins-ci.main:jenkins-coreBrowse Maven / org.jenkins-ci.main:jenkins-core | GitHub Advisory | 2.50 to < 2.414.2 · Fixed in 2.414.2 | affected |
| 2.415 to < 2.424 · Fixed in 2.424 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-43497 Jenkins Security Advisory 2023-09-20Vendor advisory
https://www.jenkins.io/security/advisory/2023-09-20