← Back to CVE List

CVE-2023-43496

Published: 2023-09-20T17:15Z
Last Modified: 2024-11-21T08:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt