Incorrect default permissions in Jenkins and Jenkins LTS - CVE-2023-43496
Published: September 21, 2023
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the system.
The vulnerability exists due to the affected plugin creates the temporary file in the system temporary directory with the default permissions for newly created files. A local user can view contents of files and directories and execute arbitrary code on the target system.
Affected software
Jenkins LTS
IBM Automation Decision Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Network Slice Selection Function
How to mitigate CVE-2023-43496
Jenkins LTS - update to 2.414.2
IBM Automation Decision Services - update to 23.0.1 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins and Jenkins LTS
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function