In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NJenkins
APPJenkins< 2.414.2< 2.424
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
Related vulnerabilities
CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓same product
Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
CVE-2017-1000353CRITICAL9.8⚠ KEVPL ✓same product
Jenkins CLI — nieuwierzytelnione RCE przez deserializację SignedObject
CVE-2023-27898CRITICAL9.6PL ✓same product
Stored XSS w Jenkins poprzez wersję wymaganą przez wtyczkę
CVE-2021-21685CRITICAL9.1PL ✓same product
Jenkins: brak kontroli dostępu przy tworzeniu katalogów przez agenta