CVE-2024-23898
Last modified
CVE-2024-23898 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.. EPSS estimates a 66.92% chance of exploitation in the next 30 days.
Description
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | >= 2.217, <= 2.441 |
| Jenkins | Jenkins | >= 2.222.1, <= 2.426.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-23898?
How severe is CVE-2024-23898?
How do I fix CVE-2024-23898?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-23892A vulnerability has been reported in Cups Easy (Purchase & I…6.1
- CVE-2024-23893A vulnerability has been reported in Cups Easy (Purchase & I…6.1
- CVE-2024-23894A vulnerability has been reported in Cups Easy (Purchase & I…6.1
- CVE-2024-23895A vulnerability has been reported in Cups Easy (Purchase & I…6.1
- CVE-2024-23896A vulnerability has been reported in Cups Easy (Purchase & I…6.1
- CVE-2024-23897Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not …9.8
- CVE-2024-23899Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier d…6.5
- CVE-2024-2390 As a part of Tenable’s vulnerability disclosure program, a …7.8
- CVE-2024-23900Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier…4.3
- CVE-2024-23901Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and …6.5
- CVE-2024-23902A cross-site request forgery (CSRF) vulnerability in Jenkins…4.3
- CVE-2024-23903Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and …5.3
Are you affected by CVE-2024-23898?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
