CVE Vulnerabilities

CVE-2024-23898

Origin Validation Error

Published: Jan 24, 2024 | Modified: May 14, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Jenkins Jenkins 2.217 (including) 2.441 (including)
Jenkins Jenkins 2.222.1 (including) 2.426.2 (including)
OCP-Tools-4.12-RHEL-8 RedHat jenkins-0:2.426.3.1706515686-3.el8 *
OCP-Tools-4.13-RHEL-8 RedHat jenkins-0:2.426.3.1706516254-3.el8 *
OpenShift Developer Tools and Services for OCP 4.11 RedHat jenkins-0:2.426.3.1706516929-3.el8 *

References