Логотип exploitDog
bind:CVE-2023-27899
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27899

Количество 4

Количество 4

redhat логотип

CVE-2023-27899

почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2023-27899

почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2023-27899

почти 3 года назад

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-hf9h-vv4m-2f33

почти 3 года назад

Incorrect Authorization in Jenkins Core

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-27899

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.

CVSS3: 7
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-27899

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.

CVSS3: 7
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-27899

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary ...

CVSS3: 7
0%
Низкий
почти 3 года назад
github логотип
GHSA-hf9h-vv4m-2f33

Incorrect Authorization in Jenkins Core

CVSS3: 7
0%
Низкий
почти 3 года назад

Уязвимостей на страницу