Back to search
CVE-2023-43498
Published: Sep 20, 2023
Modified: Sep 24, 2024
PUBLISHED
Description
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins | unaffected 2.424 - < *unaffected 2.414.2 - < 2.414.* |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now