Description
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2426 | Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution. |
Github GHSA |
GHSA-55wp-3pq4-w8p9 | Jenkins temporary plugin file created with insecure permissions |
References
History
Fri, 02 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-02T15:32:45.011Z
Reserved: 2023-09-19T09:22:58.130Z
Link: CVE-2023-43496
Updated: 2024-08-02T19:44:42.819Z
Status : Modified
Published: 2023-09-20T17:15:11.820
Modified: 2025-05-02T16:15:22.290
Link: CVE-2023-43496
OpenCVE Enrichment
No data.
EUVD
Github GHSA