Количество 5
Количество 5
CVE-2026-33002
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.
CVE-2026-33002
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.
GHSA-phhv-63fh-rrc8
Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validation
BDU:2026-04249
Уязвимость встроенного интерфейса командной строки (CLI) сервера автоматизации Jenkins, позволяющая нарушителю реализовать CSWSH-атаку (Cross-Site WebSocket Hijacking)
ROS-20260524-73-0045
Уязвимость jenkins
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33002 Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation. | CVSS3: 5.9 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33002 Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-phhv-63fh-rrc8 Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validation | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
BDU:2026-04249 Уязвимость встроенного интерфейса командной строки (CLI) сервера автоматизации Jenkins, позволяющая нарушителю реализовать CSWSH-атаку (Cross-Site WebSocket Hijacking) | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
ROS-20260524-73-0045 Уязвимость jenkins | CVSS3: 7.5 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу