Description
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.
Remediation
References
https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3072
http://www.openwall.com/lists/oss-security/2023/09/20/5
Related Vulnerabilities
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client
CVE-2022-24613 Vulnerability in maven package com.drewnoakes:metadata-extractor
CVE-2022-34805 Vulnerability in maven package org.jenkins-ci.plugins:skype-notifier
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2023-37952 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration