Bug 2260183 (CVE-2024-23899) - CVE-2024-23899 jenkins-2-plugins: git-server plugin arbitrary file read vulnerability
Summary: CVE-2024-23899 jenkins-2-plugins: git-server plugin arbitrary file read vulne...
Keywords:
Status: NEW
Alias: CVE-2024-23899
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Sayan Biswas
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2260178
TreeView+ depends on / blocked
 
Reported: 2024-01-24 20:34 UTC by Zack Miele
Modified: 2024-11-30 08:27 UTC (History)
6 users (show)

Fixed In Version: git-server 99.101.v720e86326c09
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:3634 0 None None None 2024-06-05 14:44:27 UTC
Red Hat Product Errata RHSA-2024:3635 0 None None None 2024-06-05 14:44:59 UTC
Red Hat Product Errata RHSA-2024:3636 0 None None None 2024-06-05 14:43:55 UTC
Red Hat Product Errata RHSA-2024:4597 0 None None None 2024-07-17 18:46:59 UTC

Description Zack Miele 2024-01-24 20:34:05 UTC
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

http://www.openwall.com/lists/oss-security/2024/01/24/6
https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3319

Comment 6 errata-xmlrpc 2024-06-05 14:43:54 UTC
This issue has been addressed in the following products:

  OCP-Tools-4.13-RHEL-8

Via RHSA-2024:3636 https://access.redhat.com/errata/RHSA-2024:3636

Comment 7 errata-xmlrpc 2024-06-05 14:44:26 UTC
This issue has been addressed in the following products:

  OCP-Tools-4.14-RHEL-8

Via RHSA-2024:3634 https://access.redhat.com/errata/RHSA-2024:3634

Comment 8 errata-xmlrpc 2024-06-05 14:44:58 UTC
This issue has been addressed in the following products:

  OCP-Tools-4.12-RHEL-8

Via RHSA-2024:3635 https://access.redhat.com/errata/RHSA-2024:3635

Comment 9 errata-xmlrpc 2024-07-17 18:46:58 UTC
This issue has been addressed in the following products:

  OCP-Tools-4.15-RHEL-8

Via RHSA-2024:4597 https://access.redhat.com/errata/RHSA-2024:4597


Note You need to log in before you can comment on or make changes to this bug.