Improper access control in Jenkins and Jenkins LTS - CVE-2024-47804
Published: October 7, 2024
Vulnerability identifier: #VU98065
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47804
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to item creation restriction bypass issue. A remote user can bypass the restrictions and create a temporary item.
Affected software
Jenkins
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2024-47804
Install updates from vendor's website.
Jenkins - update to 2.479
Jenkins LTS - update to 2.462.3
jenkins (Red Hat package) - addressed in versions 2.462.3.1729837947-3.el8, 2.462.3.1729839727-3.el8, 2.462.3.1729839924-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1730119231-1.el8, 4.13.1729840148-1.el8, 4.14.1729839844-1.el8, 4.15.1729838165-1.el8
Jenkins LTS - update to 2.462.3
jenkins (Red Hat package) - addressed in versions 2.462.3.1729837947-3.el8, 2.462.3.1729839727-3.el8, 2.462.3.1729839924-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1730119231-1.el8, 4.13.1729840148-1.el8, 4.14.1729839844-1.el8, 4.15.1729838165-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins and Jenkins LTS
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Red Hat Product OCP Tools 4 update for Openshift Jenkins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function