Path traversal in Folders - CVE-2023-40338
Published: August 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected plugin displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
OpenShift Developer Tools and Services
IBM Cloud Pak for Business Automation
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2023-40338
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
jenkins (Red Hat package) - addressed in versions 2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1706515741-1.el8, 4.14.1706516441-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins Folders plugin
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- OpenShift Developer Tools and Services for OCP 4.14 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.12 update for Jenkins and Jenkins-2-plugins