Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27899


Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.


Published

2023-03-10T21:15:15.460

Last Modified

2025-02-28T19:15:35.080

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins jenkins < 2.375.4 Yes
Application jenkins jenkins < 2.394 Yes

References