QID 995342
Date Published: 2023-09-22
QID 995342: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-hq87-h4jg-vxfw)
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, uploaded files processed via the Stapler web framework and the Jenkins API MultipartFormDataParser create temporary files in the system temporary directory with the default permissions for newly created files.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hq87-h4jg-vxfw for updates and patch information.
Vendor References
- GHSA-hq87-h4jg-vxfw -
github.com/advisories/GHSA-hq87-h4jg-vxfw
CVEs related to QID 995342
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hq87-h4jg-vxfw | org.jenkins-ci.main:jenkins-core |
|