Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-23898

Опубликовано: 24 янв. 2024
Источник: debian

Описание

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsremovedpackage

Связанные уязвимости

CVSS3: 8.8
redhat
около 2 лет назад

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

CVSS3: 8.8
nvd
около 2 лет назад

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

CVSS3: 8.8
github
около 2 лет назад

Cross-site WebSocket hijacking vulnerability in the Jenkins CLI

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость встроенного интерфейса командной строки (CLI) сервера автоматизации Jenkins, позволяющая нарушителю реализовать CSWSH-атаку

CVSS3: 8.8
redos
почти 2 года назад

Множественные уязвимости jenkins