Improper access control in Jenkins and Jenkins LTS - CVE-2024-47804

 

Improper access control in Jenkins and Jenkins LTS - CVE-2024-47804

Published: October 7, 2024


Vulnerability identifier: #VU98065
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47804
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to item creation restriction bypass issue. A remote user can bypass the restrictions and create a temporary item.


Affected software

Jenkins
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-47804

Install updates from vendor's website.

Jenkins - update to 2.479
Jenkins LTS - update to 2.462.3
jenkins (Red Hat package) - addressed in versions 2.462.3.1729837947-3.el8, 2.462.3.1729839727-3.el8, 2.462.3.1729839924-3.el8, 2.462.3.1730119132-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1730119231-1.el8, 4.13.1729840148-1.el8, 4.14.1729839844-1.el8, 4.15.1729838165-1.el8

External References

Related Security Bulletins