CVE-2024-23899
jenkins-2-plugins: git-server plugin arbitrary file read vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.
El complemento del servidor Jenkins Git 99.va_0826a_b_cdfa_d y versiones anteriores no desactiva una función de su analizador de comandos que reemplaza un carácter '@' seguido de una ruta de archivo en un argumento con el contenido del archivo, permitiendo a atacantes con permiso general/lectura leer contenido de archivos arbitrarios en el sistema de archivos del controlador Jenkins.
A flaw was found in the Git Server Plugin for Jenkins. This issue could allow an attacker to read the first two lines of arbitrary files on the server's file system.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-23 CVE Reserved
- 2024-01-24 CVE Published
- 2024-02-01 EPSS Updated
- 2024-10-18 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/01/24/6 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3319 | 2024-01-31 | |
https://access.redhat.com/security/cve/CVE-2024-23899 | 2024-07-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2260183 | 2024-07-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Git Server Search vendor "Jenkins" for product "Git Server" | <= 99.va_0826a_b_cdfa_d Search vendor "Jenkins" for product "Git Server" and version " <= 99.va_0826a_b_cdfa_d" | jenkins |
Affected
|