)]}'
{
  "commit": "93a2c057829cdbc9abb8189038c05f9ad26fa5c6",
  "tree": "9781763fb0ffd2f302285f53fd30e708a9ff8214",
  "parents": [
    "ba36a085ae4dc0f73e084433b83876969558f941"
  ],
  "author": {
    "name": "Luca Milanesio",
    "email": "luca.milanesio@gmail.com",
    "time": "Mon Jan 29 20:26:03 2024 +0000"
  },
  "committer": {
    "name": "Luca Milanesio",
    "email": "luca.milanesio@gmail.com",
    "time": "Mon Jan 29 21:43:17 2024 +0000"
  },
  "message": "Add workaround for mitigating CVE-2024-23897\n\nThe CVE-2024-23897 allows any anonymous user to access\nany files on the filesystem by exploiting the ability\nof args4j to access files content as parameters.\n\nUntil Jenkins gets upgraded to at least 2.442, LTS 2.426.3\nmake sure that the CLI is fully disabled, using the workaround\nsuggested at [1].\n\n[1] https://www.jenkins.io/security/advisory/2024-01-24/\n\nBug: Issue 322839800\nChange-Id: I1bd6d8c2506ff0cc9cf40b76f2306b080d0a7ef8\n",
  "tree_diff": [
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "ba967cf15b2225b262c60b57071d64dc80516d88",
      "new_mode": 33188,
      "new_path": "jenkins-docker/server/CVE-2024-23897-disable-cli.groovy"
    },
    {
      "type": "modify",
      "old_id": "ffd9f022f7eb173f64ea792c9e4105321bcf8b33",
      "old_mode": 33188,
      "old_path": "jenkins-docker/server/Dockerfile",
      "new_id": "45af17067293aa22e6fd373a866d8b01bc459f03",
      "new_mode": 33188,
      "new_path": "jenkins-docker/server/Dockerfile"
    }
  ]
}
