Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-27903
HistoryMar 08, 2023 - 5:14 p.m.

CVE-2023-27903

2023-03-0817:14:52
jenkins
www.cve.org
8
cve-2023-27903
jenkins
temporary file
default permissions
file system access

AI Score

5.2

Confidence

High

EPSS

0

Percentile

13.3%

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Jenkins",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThan": "*",
        "status": "unaffected",
        "version": "2.394",
        "versionType": "maven"
      },
      {
        "lessThan": "2.375.*",
        "status": "unaffected",
        "version": "2.375.4",
        "versionType": "maven"
      },
      {
        "lessThan": "2.387.*",
        "status": "unaffected",
        "version": "2.387.1",
        "versionType": "maven"
      }
    ]
  }
]

AI Score

5.2

Confidence

High

EPSS

0

Percentile

13.3%