PT-2023-21408 · Jenkins · Jenkins
Markus Winter
·
Published
2023-03-08
·
Updated
2025-02-28
·
CVE-2023-27902
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.393 and earlier
Jenkins LTS versions 2.375.3 and earlier
Jenkins versions prior to LTS 2.387.1
Description
The issue allows attackers with Item/Workspace permission to access the contents of temporary directories related to job workspaces. These temporary directories are used by Jenkins to store temporary files related to the build and may contain credentials stored by Jenkins-controlled processes.
Recommendations
For Jenkins versions 2.393 and earlier, consider updating to version 2.394 or later.
For Jenkins LTS versions 2.375.3 and earlier, consider updating to version 2.375.4 or later.
For versions prior to LTS 2.387.1, consider updating to version LTS 2.387.1 or later.
As a temporary workaround, do not grant Item/Workspace permission to users who lack Item/Configure permission.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins