Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1031 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution. |
Github GHSA |
GHSA-hf9h-vv4m-2f33 | Incorrect Authorization in Jenkins Core |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-28T18:36:45.296Z
Reserved: 2023-03-07T09:35:48.506Z
Link: CVE-2023-27899
Updated: 2024-08-02T12:23:30.612Z
Status : Modified
Published: 2023-03-10T21:15:15.460
Modified: 2025-02-28T19:15:35.080
Link: CVE-2023-27899
OpenCVE Enrichment
No data.
EUVD
Github GHSA