Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27902

Опубликовано: 10 мар. 2023
Источник: redhat
CVSS3: 4.3

Описание

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.

A flaw was found in Jenkins. Jenkins uses temporary directories adjacent to workspace directories, usually with the @tmp name suffix, to store temporary files related to the build. In pipelines, these temporary directories are adjacent to the current working directory when operating in a subdirectory of the automatically allocated workspace. Jenkins-controlled processes, like SCMs, may store credentials in these directories. Affected versions of Jenkins show these temporary directories when viewing job workspaces, which allows attackers with Item/Workspace permission to access their contents.

Отчет

OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of the scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as Out of Support Scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkinsOut of support scope
Red Hat OpenShift Container Platform 4jenkinsAffected
OCP-Tools-4.13-RHEL-8jenkinsFixedRHSA-2023:329924.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2177630Jenkins: Workspace temporary directories accessible through directory browser

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.

CVSS3: 4.3
debian
почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary dir ...

CVSS3: 4.3
github
почти 3 года назад

Incorrect Permission Preservation in Jenkins Core

4.3 Medium

CVSS3