Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-43498


In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.


Published

2023-09-20T17:15:11.927

Last Modified

2024-11-21T08:24:09.730

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-377

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins jenkins < 2.414.2 Yes
Application jenkins jenkins < 2.424 Yes

References