PT-2023-21408 · Jenkins · Jenkins

Markus Winter

·

Published

2023-03-08

·

Updated

2025-02-28

·

CVE-2023-27902

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.393 and earlier Jenkins LTS versions 2.375.3 and earlier Jenkins versions prior to LTS 2.387.1
Description The issue allows attackers with Item/Workspace permission to access the contents of temporary directories related to job workspaces. These temporary directories are used by Jenkins to store temporary files related to the build and may contain credentials stored by Jenkins-controlled processes.
Recommendations For Jenkins versions 2.393 and earlier, consider updating to version 2.394 or later. For Jenkins LTS versions 2.375.3 and earlier, consider updating to version 2.375.4 or later. For versions prior to LTS 2.387.1, consider updating to version LTS 2.387.1 or later. As a temporary workaround, do not grant Item/Workspace permission to users who lack Item/Configure permission.

Exploit

Fix

Related Identifiers

BIT-JENKINS-2023-27902
CVE-2023-27902
GHSA-CJ6R-8PXJ-5JV6
RHSA-2023:3299

Affected Products

Jenkins