LOW 3.1
GHSA-rrgp-c2w8-6vg6
Information disclosure through error stack traces related to agents
Quick fix
GHSA-rrgp-c2w8-6vg6 — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.387.1</version> for org.jenkins-ci.main:jenkins-core Details
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier, and prior to LTS 2.387.1 prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Jenkins 2.394, LTS 2.375.4, and LTS 2.387.1 does not display error stack traces when agent connections are broken.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.jenkins-ci.main:jenkins-core
Introduced in:
2.376 Fixed in: 2.387.1 Fix
# pom.xml: bump <version>2.387.1</version> for org.jenkins-ci.main:jenkins-core Maven / org.jenkins-ci.main:jenkins-core
Introduced in:
0 Fixed in: 2.375.4 Fix
# pom.xml: bump <version>2.375.4</version> for org.jenkins-ci.main:jenkins-core Maven / org.jenkins-ci.main:jenkins-core
Introduced in:
2.388 Fixed in: 2.394 Fix
# pom.xml: bump <version>2.394</version> for org.jenkins-ci.main:jenkins-core References
- https://nvd.nist.gov/vuln/detail/CVE-2023-27904 [ADVISORY]
- https://github.com/jenkinsci/jenkins/commit/40663588eea4ac953209bd8845b6b880792f92cc [WEB]
- https://github.com/CVEProject/cvelist/blob/master/2023/27xxx/CVE-2023-27904.json [WEB]
- https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-2120 [WEB]