Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23899

Опубликовано: 09 янв. 2024
Источник: redhat
CVSS3: 8.8

Описание

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

A flaw was found in the Git Server Plugin for Jenkins. This issue could allow an attacker to read the first two lines of arbitrary files on the server's file system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
OCP-Tools-4.12-RHEL-8jenkinsFixedRHSA-2024:363505.06.2024
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2024:363505.06.2024
OCP-Tools-4.13-RHEL-8jenkinsFixedRHSA-2024:363605.06.2024
OCP-Tools-4.13-RHEL-8jenkins-2-pluginsFixedRHSA-2024:363605.06.2024
OCP-Tools-4.14-RHEL-8jenkinsFixedRHSA-2024:363405.06.2024
OCP-Tools-4.14-RHEL-8jenkins-2-pluginsFixedRHSA-2024:363405.06.2024
OCP-Tools-4.15-RHEL-8jenkinsFixedRHSA-2024:459717.07.2024
OCP-Tools-4.15-RHEL-8jenkins-2-pluginsFixedRHSA-2024:459717.07.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2260183jenkins-2-plugins: git-server plugin arbitrary file read vulnerability

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

CVSS3: 8.8
github
больше 1 года назад

Arbitrary file read vulnerability in Git server Plugin can lead to RCE

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость библиотеки args4j плагина Jenkins Git server Plugin, позволяющая нарушителю читать первые две строки произвольных файлов

CVSS3: 8.8
redos
около 1 года назад

Множественные уязвимости jenkins

8.8 High

CVSS3