Description
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-53ph-2r2x-vqw8 | Cross-site WebSocket hijacking vulnerability in the Jenkins CLI |
References
History
Fri, 20 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-06-20T19:28:50.201Z
Reserved: 2024-01-23T12:46:51.264Z
Link: CVE-2024-23898
Updated: 2024-08-01T23:13:08.509Z
Status : Modified
Published: 2024-01-24T18:15:09.420
Modified: 2025-06-20T20:15:31.930
Link: CVE-2024-23898
OpenCVE Enrichment
No data.
Github GHSA