We found results for “”
CVE-2023-43498
Good to know:
Date: September 20, 2023
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Insufficient Information
NVD-CWE-noinfoInsecure Temporary File
CWE-377Top Fix
Upgrade Version
Upgrade to version org.jenkins-ci.main:jenkins-core:2.424;org.jenkins-ci.main:jenkins-core:2.414.2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


