

ewterz Threat Alert –Fabookie: A Stealthy InfoStealer Threat Targeting Social Media Accounts – Active IOCs
January 30, 2024
Rewterz Threat Alert –Microsoft Outlook Vulnerability Possibly Exploited by Threat Actors to Leak NTLM Passwords
January 30, 2024
ewterz Threat Alert –Fabookie: A Stealthy InfoStealer Threat Targeting Social Media Accounts – Active IOCs
January 30, 2024
Rewterz Threat Alert –Microsoft Outlook Vulnerability Possibly Exploited by Threat Actors to Leak NTLM Passwords
January 30, 2024Severity
Medium
Analysis Summary
CVE-2024-23899 CVSS:8.8
Jenkins Git server Plugin could allow a remote authenticated attacker to obtain sensitive information, caused by not disable a feature of its command parser that replaces an ‘@’ character followed by a file path in an argument with the file’s contents. By sending a specially crafted request, an attacker could exploit this vulnerability to read content from arbitrary files on the Jenkins controller file system, and use this information to launch further attacks against the affected system.
CVE-2024-23900 CVSS:4.6
Jenkins Matrix Project Plugin could allow a remote authenticated attacker to traverse directories on the system, caused by not sanitize user-defined axis names of multi-configuration projects. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to replace arbitrary config.xml files on the Jenkins controller file system.
CVE-2024-23901 CVSS:5.4
Jenkins GitLab Branch Source Plugin could allow a remote attacker to bypass security restrictions, caused by a flaw with shared projects are unconditionally discovered. By sending a specially crafted request, an attacker could exploit this vulnerability to configure and share a project.
CVE-2024-23902 CVSS:4.3
Jenkins GitLab Branch Source Plugin is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to connect to an attacker-specified URL. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
CVE-2024-23903 CVSS:3.7
Jenkins GitLab Branch Source Plugin could allow a remote attacker to obtain sensitive information, caused by the use of a non-constant time comparison function when checking whether the provided and expected webhook token are equal. By utilize statistical method attack techniques, an attacker could exploit this vulnerability to obtain a valid webhook token information, and use this information to launch further attacks against the affected system.
CVE-2024-23904 CVSS:7.5
Jenkins Log Command Plugin could allow a remote attacker to obtain sensitive information, caused by not disable a feature of its command parser that replaces an ‘@’ character followed by a file path in an argument with the file’s contents. By sending a specially crafted request, an attacker could exploit this vulnerability to read content from arbitrary files on the Jenkins controller file system, and use this information to launch further attacks against the affected system.
CVE-2024-23905 CVSS:8
Jenkins Red Hat Dependency Analytics Plugin is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Impact
- Gain Access
- Security Bypass
- Cross-Site Scripting
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2024-23899
- CVE-2024-23900
- CVE-2024-23901
- CVE-2023-23902
- CVE-2024-23903
- CVE-2024-23904
- CVE-2024-23905
Affected Vendors
Jenkins
Affected Products
- Jenkins Log Command Plugin 1.0.2
- Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3
- Jenkins Git server Plugin 99.va_0826a_b_cdfa_d
- Jenkins Red Hat Dependency Analytics Plugin 0.7.1
- Jenkins Matrix Project Plugin 822.v01b_8c85d16d2
Remediation
Refer to Jenkins Security Advisory for patch, upgrade or suggested workaround information.