← Back to browse · API

CVE-2024-23898

Severity
HIGH
CVSS
8.8
EPSS
0.67151
Risk score
58.7
CISA KEV
No
PoC
No
Published
2024-01-24
Modified
2025-06-20
First seen
2026-08-07
Aliases
EUVD-2024-0256, GHSA-53PH-2R2X-VQW8
Products
Jenkins Project:Jenkins, Jenkins Project:Jenkins patch: 0, Jenkins Project:Jenkins patch: 2.426.3, Jenkins Project:Jenkins patch: 2.440.1, Jenkins Project:Jenkins patch: 2.442
Sources
euvd EUVD-2024-0256

Description

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.

References