QID 730932
Date Published: 2023-10-16
QID 730932: Jenkins Multiple Security Vulnerabilities (Jenkins Security Advisory 2023-09-20)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
CVE-2023-43494: Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from this search.
CVE-2023-43495: Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the caption constructor parameter of ExpandableDetailsNote.
Affected Versions:
Jenkins weekly up to and including 2.423
Jenkins LTS up to and including 2.414.1
Fixed Versions:
Jenkins weekly should be updated to version 2.424
Jenkins LTS should be updated to version 2.414.2
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a crafted GET request to Jenkins. This QID also detects the vulnerable version from login page or HTTP header.
Successful exploitation of this vulnerability may allow attackers with Item/Read permission to obtain values of sensitive variables used in builds or execute arbitrary JavaScript code on the targeted user's browser.
For further details refer to Jenkins Security Advisory 2023-09-20
- Jenkins Security Advisory 2023-09-20 -
www.jenkins.io/security/advisory/2023-09-20/
CVEs related to QID 730932
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Jenkins Security Advisory 2023-09-20 |
|