CVE-2024-23898

CVSS v3.1 8.8 (High)
88% Progress
EPSS 0.07 % (32th)
0.07% Progress
Affected Products 1
Advisories 3
NVD Status Modified

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

Weaknesses
CWE-346
Origin Validation Error
CVE Status
PUBLISHED
NVD Status
Modified
CNA
Jenkins Project
Published Date
2024-01-24 18:15:09
(7 months ago)
Updated Date
2024-05-14 15:01:24
(4 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins from 2.217 version and 2.441 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:- >= 2.217 <= 2.441
  Jenkins from 2.222.1 version and 2.426.2 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:lts >= 2.222.1 <= 2.426.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...