Vulnerabilities > CVE-2023-27899 - Incorrect Authorization vulnerability in Jenkins

047910
CVSS 7.0 - HIGH
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
high complexity
jenkins
CWE-863

Summary

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.

Vulnerable Configurations

Part Description Count
Application
Jenkins
1092

Common Weakness Enumeration (CWE)