CVE-2024-23898

HIGHCVSS 8.8/10EPSS 66.92%

Last modified

CVE-2024-23898 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.. EPSS estimates a 66.92% chance of exploitation in the next 30 days.

Description

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
66.92%

99.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JenkinsJenkins>= 2.217, <= 2.441
JenkinsJenkins>= 2.222.1, <= 2.426.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-23898?
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.
How severe is CVE-2024-23898?
CVE-2024-23898 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 66.92% probability of exploitation in the next 30 days.
How do I fix CVE-2024-23898?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-23898?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST