Jenkins CLI WebSocket Endpoint Vulnerability

CVE-2024-23898
8.8HIGH

Key Information

Vendor
Jenkins
Status
Jenkins
Vendor
CVE Published:
24 January 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

Affected Version(s)

Jenkins <= 0

Jenkins >= 2.217

Jenkins >= 2.442

News Articles

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • First article discovered by The Stack

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database2 News Article(s)
.