Korean
<< Back
VID 210269
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description According to its its self-reported version number, the version of Jenkins running on the remote web server is Jenkins LTS prior to 2.426.3 or Jenkins weekly prior to 2.442. It is, therefore, affected by multiple vulnerabilities:

- Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. (CVE-2024-23897)
- Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller. (CVE-2024-23898)

* References:
https://jenkins.io/security/advisory/2024-01-24

* Platforms Affected:
Jenkins all versions equal to or lower than 2.442
Any operating system Any version
Recommendation Upgrade to the latest version of Jenkins (2.442 or later), available from the Jenkins Software Foundation download site, https://jenkins.io/download
Related URL CVE-2024-23897,CVE-2024-23898 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)