Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84649

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

A flaw was found in Stapler, a web framework used by Jenkins. An HTTP endpoint that serves dynamically generated JavaScript resources inadvertently embeds a user's cross-site request forgery (CSRF) token, also known as a crumb, as plain text. This allows a remote attacker, who controls a web page on the same site as Jenkins, to obtain a valid crumb for a targeted user's session. Consequently, the attacker can perform unauthorized actions on behalf of the user, leading to session hijacking.

Отчет

This Important vulnerability in Stapler, as used in Jenkins, allows an attacker to perform session hijacking. By controlling a web page on the same site as Jenkins, an attacker can hijack a user's token through cross-site request forgery (CSRF), enabling unauthorized actions. This risk is elevated when the Resource Root URL is configured on the same domain as the Jenkins URL.

Меры по смягчению последствий

To mitigate this issue, administrators should disable the Resource Root URL feature in Jenkins or configure it to use a different domain than the main Jenkins instance. This prevents an attacker from loading dynamically generated JavaScript resources containing the CSRF token from a co-hosted page.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2527605jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking

EPSS

Процентиль: 6%
0.00168
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
14 дней назад

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

CVSS3: 8.8
github
14 дней назад

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

EPSS

Процентиль: 6%
0.00168
Низкий

8.1 High

CVSS3