CVE-2024-23898 Information
Jan 25, 2024
cve
Description
Jenkins 2.217 through 2.441 (both inclusive) LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability allowing attackers to execute CLI commands on the Jenkins controller.
Reference
https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3315 http://www.openwall.com/lists/oss-security/2024/01/24/6
Share on: