Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32981

Опубликовано: 16 мая 2023
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.

A flaw was found in the Jenkins Pipeline Utility Steps Plugin. This flaw allows a remote, authenticated attacker to traverse directories on the system, caused by improper archive file validation. The attacker can use a specially crafted archive file containing "dot dot" sequences (/../) to create or replace arbitrary files on the agent file system with attacker-specified content.

Отчет

OpenShift 3.11 is in ELS. Jenkins and its related technologies will not be supported under ELS. Hence, OpenShift 3.11 is marked as affected/won'tfix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2023:361015.06.2023
OpenShift Developer Tools and Services for OCP 4.11jenkins-2-pluginsFixedRHSA-2023:366319.06.2023
Red Hat OpenShift Container Platform 4.10jenkins-2-pluginsFixedRHSA-2023:362523.06.2023

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2207835jenkins-2-plugin: pipeline-utility-steps: Arbitrary file write vulnerability on agents in Pipeline Utility Steps Plugin

EPSS

Процентиль: 73%
0.00784
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.

CVSS3: 6.3
github
больше 2 лет назад

Jenkins Pipeline Utility Steps Plugin arbitrary file write vulnerability

EPSS

Процентиль: 73%
0.00784
Низкий

6.3 Medium

CVSS3

Уязвимость CVE-2023-32981