CVE-2023-24439
published 2023-01-26CVE-2023-24439: Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.4th percentile
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitpython_project | gitpython | >= 0 < 3.1.32 | 3.1.32 |
| jenkins | bearychat_plugin | — | — |
| jenkins | bitbucket_oauth_plugin | — | — |
| jenkins | cisco_spark_notifier_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | github_pull_request_builder_plugin | — | — |
| jenkins | github_pull_request_coverage_status_plugin | — | — |
| jenkins | ids_in_orka_by_macstadium_plugin | — | — |
| jenkins | jira_pipeline_steps | <= 2.0.165.v8846cf59f3db | — |
| jenkins | jira_pipeline_steps_plugin | — | — |
| jenkins | keycloak_authentication_plugin | — | — |
| jenkins | kubernetes_credentials_provider_plugin | — | — |
| jenkins | macstadium_plugin | — | — |
| jenkins | mstest_plugin | — | — |
| jenkins | openid_connect_authentication_plugin | — | — |
| jenkins | openid_plugin | — | — |
| jenkins | orka_by_macstadium_plugin | — | — |
| jenkins | pwauth_security_realm_plugin | — | — |
| jenkins | rabbitmq_consumer_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | semantic_versioning_plugin | — | — |
| jenkins | testcomplete_support_plugin | — | — |
| jenkins | testquality_updater_plugin | — | — |
| jenkins_project | jenkins_jira_pipeline_steps_plugin | unspecified – 2.0.165.v8846cf59f3db | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa9.8CRITICAL
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
ghsa·2023-08-11·CVSS 9.8
CVE-2023-40267 [HIGH] CWE-78 GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
GitPython before 3.1.32 does not block insecure non-multi options in `clone` and `clone_from`, making it vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
OSV
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
osv·2023-01-26
CVE-2023-24439 [MEDIUM] Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
GHSA
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
ghsa·2023-01-26
CVE-2023-24439 [MEDIUM] CWE-256 Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Red Hat
GitPython: Insecure non-multi options in clone and clone_from is not blocked
vendor_redhat·2023-08-11·CVSS 8.1
CVE-2023-40267 [HIGH] CWE-20 GitPython: Insecure non-multi options in clone and clone_from is not blocked
GitPython: Insecure non-multi options in clone and clone_from is not blocked
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
An improper input validation vulnerability was found in GitPython. This flaw allows an attacker to inject a maliciously crafted remote URL into the clone command, possibly leading to remote code execution.
Statement: In Red Hat Openstack, Red Hat Ansible Automation Platform, and Red Hat Certification Program, while the gitpython dependency is present, the affected codebase is not being used.
Red Hat Satellite does not use the affected functions during runtime, therefore the possible impact is limited to Moderate.
Package: gitpython (Red Hat Ansible
Jenkins
Jenkins Security Advisory 2023-01-24
vendor_jenkins·2023-01-24·CVSS 8.8
CVE-2023-24422 [HIGH] Jenkins Security Advisory 2023-01-24
Title: Jenkins Security Advisory 2023-01-24
Jenkins Security Advisory 2023-01-24
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
BearyChat
Plugin
Bitbucket OAuth
Plugin
Cisco Spark Notifier
Plugin
Gerrit Trigger
Plugin
GitHub Pull Request Builder
Plugin
GitHub Pull Request Coverage Status
Plugin
No detection rules found.
No public exploits indexed.
2023-01-26
Published