Back to search
CVE-2023-43496
Published: Sep 20, 2023
Modified: May 2, 2025
PUBLISHED
Description
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins | unaffected 2.424 - < *unaffected 2.414.2 - < 2.414.* |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now