CVE-2023-27904: Infoleak
A flaw was found in Jenkins. The affected version of Jenkins prints an error stack trace on agent-related pages when agent connections are broken. This stack trace may contain information about Jenkins configuration that is otherwise inaccessible to attackers.
Other sources
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier, and prior to LTS 2.387.1 prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Jenkins 2.394, LTS 2.375.4, and LTS 2.387.1 does not display error stack traces when agent connections are broken.
Jenkins 2.393 and earlier, LTS 2.375.3, and earlier print an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-2120
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2023-27904?
The severity of CVE-2023-27904 is medium with a CVSS score of 5.3.
How does CVE-2023-27904 affect Jenkins?
CVE-2023-27904 affects Jenkins versions up to 2.393 and LTS versions up to 2.375.3.
How can I mitigate the vulnerability in Jenkins?
To mitigate the vulnerability in Jenkins, update to version 2.394.
What information can the error stack trace in CVE-2023-27904 expose?
The error stack trace in CVE-2023-27904 may expose Jenkins configuration information that is otherwise inaccessible to attackers.
Where can I find more information about CVE-2023-27904?
You can find more information about CVE-2023-27904 on the official Jenkins security advisory and the NVD website.