Bug 2177632 (CVE-2023-27903) - CVE-2023-27903 Jenkins: Temporary file parameter created with insecure permissions
Summary: CVE-2023-27903 Jenkins: Temporary file parameter created with insecure permis...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2023-27903
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2177137
TreeView+ depends on / blocked
 
Reported: 2023-03-13 08:26 UTC by Avinash Hanwate
Modified: 2024-02-12 10:43 UTC (History)
8 users (show)

Fixed In Version: Jenkins 2.394, LTS 2.375.4, LTS 2.387.1
Doc Type: ---
Doc Text:
A flaw was found in Jenkins. When triggering a build from the Jenkins CLI, Jenkins creates a temporary file on the controller if a file parameter is provided through the CLI’s standard input. Affected versions of Jenkins create this temporary file in the default temporary directory with the default permissions for newly created files. If these permissions are overly permissive, they may allow attackers with access to the Jenkins controller file system to read and write the file before it is used in the build.
Clone Of:
Environment:
Last Closed: 2023-04-12 18:05:48 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:1655 0 None None None 2023-04-12 11:59:07 UTC
Red Hat Product Errata RHSA-2023:3195 0 None None None 2023-05-17 16:19:36 UTC
Red Hat Product Errata RHSA-2023:3198 0 None None None 2023-05-17 17:51:12 UTC
Red Hat Product Errata RHSA-2023:3622 0 None None None 2023-06-15 09:01:27 UTC
Red Hat Product Errata RHSA-2023:3663 0 None None None 2023-06-19 10:13:12 UTC
Red Hat Product Errata RHSA-2024:0775 0 None None None 2024-02-12 10:43:54 UTC
Red Hat Product Errata RHSA-2024:0778 0 None None None 2024-02-12 10:36:54 UTC

Description Avinash Hanwate 2023-03-13 08:26:55 UTC
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used.

https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-3058

Comment 4 errata-xmlrpc 2023-04-12 11:59:05 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.10

Via RHSA-2023:1655 https://access.redhat.com/errata/RHSA-2023:1655

Comment 5 Product Security DevOps Team 2023-04-12 18:05:47 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-27903

Comment 10 errata-xmlrpc 2023-05-17 16:19:35 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.12

Via RHSA-2023:3195 https://access.redhat.com/errata/RHSA-2023:3195

Comment 11 errata-xmlrpc 2023-05-17 17:51:10 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.11

Via RHSA-2023:3198 https://access.redhat.com/errata/RHSA-2023:3198

Comment 12 errata-xmlrpc 2023-06-15 09:01:26 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.13

Via RHSA-2023:3622 https://access.redhat.com/errata/RHSA-2023:3622

Comment 13 errata-xmlrpc 2023-06-19 10:13:10 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.11

Via RHSA-2023:3663 https://access.redhat.com/errata/RHSA-2023:3663

Comment 16 errata-xmlrpc 2024-02-12 10:36:53 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.12

Via RHSA-2024:0778 https://access.redhat.com/errata/RHSA-2024:0778

Comment 17 errata-xmlrpc 2024-02-12 10:43:52 UTC
This issue has been addressed in the following products:

  OpenShift Developer Tools and Services for OCP 4.11

Via RHSA-2024:0775 https://access.redhat.com/errata/RHSA-2024:0775


Note You need to log in before you can comment on or make changes to this bug.