PT-2024-1425 · Jenkins+1 · Jenkins Git Server Plugin+2

Published

2024-01-24

·

Updated

2024-04-11

·

CVE-2024-23899

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Git server Plugin versions 99.va 0826a b cdfa d and earlier
Description The issue is related to the command parser feature in the Jenkins Git server Plugin that replaces an '@' character followed by a file path in an argument with the file's contents. This allows attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited.
Recommendations For Jenkins Git server Plugin versions 99.va 0826a b cdfa d and earlier, update to version 99.101.v720e86326c09 or later to disable the command parser feature that replaces an '@' character followed by a file path in an argument with the file’s contents. As a temporary workaround, navigate to Manage Jenkins » Security and ensure that the SSHD Port setting in the SSH Server section is set to Disable to prevent access to Git repositories hosted by Jenkins via SSH.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-00899
CVE-2024-23899
GHSA-VPH5-2Q33-7R9H
RHSA-2024:3634
RHSA-2024:3635
RHSA-2024:3636
RHSA-2024:4597

Affected Products

Jenkins
Jenkins Git Server Plugin
Red Os