CVE-2023-43497
Summary
| CVE | CVE-2023-43497 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 17:15:00 UTC |
| Updated | 2023-09-23 03:45:00 UTC |
| Description | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Multiple vulnerabilities in Jenkins and Jenkins plugins | MISC | www.openwall.com | |
| Jenkins Security Advisory 2023-09-20 | MISC | www.jenkins.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 691306 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (402fccd0-5b6d-11ee-9898-00e081b7aa2d)
- 730933 Jenkins Multiple Security Misconfiguration Vulnerabilities (Jenkins Security Advisory 2023-09-20)
- 995334 Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-qv64-w99c-qcr9)