Incorrect default permissions in Jenkins and Jenkins LTS - CVE-2023-43496

 

Incorrect default permissions in Jenkins and Jenkins LTS - CVE-2023-43496

Published: September 21, 2023


Vulnerability identifier: #VU80937
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43496
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the system.

The vulnerability exists due to the affected plugin creates the temporary file in the system temporary directory with the default permissions for newly created files. A local user can view contents of files and directories and execute arbitrary code on the target system.


Affected software

Jenkins
Jenkins LTS
IBM Automation Decision Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Network Slice Selection Function

How to mitigate CVE-2023-43496

Install updates from vendor's website.

Jenkins - update to 2.424
Jenkins LTS - update to 2.414.2
IBM Automation Decision Services - update to 23.0.1 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5

External References

Related Security Bulletins