PT-2024-1303 · Jenkins+1 · Jenkins+1

Yaniv Nizry

·

Published

2024-01-24

·

Updated

2024-05-14

·

CVE-2024-23898

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.217 through 2.441 Jenkins LTS versions 2.222.1 through 2.426.2
Description The issue is related to the built-in command line interface (CLI) of the Jenkins server, which has a weakness in its authentication procedure. This weakness can be exploited by a remote attacker to perform a cross-site WebSocket hijacking (CSWSH) attack, allowing the execution of CLI commands on the Jenkins controller. The vulnerability is due to the lack of origin validation of requests made through the CLI WebSocket endpoint.
Recommendations For Jenkins versions 2.217 through 2.441, update to a version that includes the fix for this issue. For Jenkins LTS versions 2.222.1 through 2.426.2, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the CLI WebSocket endpoint until a patch is available. Restrict access to the Jenkins controller to minimize the risk of exploitation.

Fix

DoS

Origin Validation Error

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00751
BIT-JENKINS-2024-23898
CVE-2024-23898
GHSA-53PH-2R2X-VQW8
RHSA-2024:0775
RHSA-2024:0776
RHSA-2024:0778

Affected Products

Jenkins
Red Os