VID |
210270 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
According to its its self-reported version number, the version of Jenkins running on the remote web server is Jenkins LTS prior to 2.426.3 or Jenkins weekly prior to 2.442. It is, therefore, affected by multiple vulnerabilities:
- Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. (CVE-2024-23897) - Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller. (CVE-2024-23898)
* References: https://jenkins.io/security/advisory/2024-01-24
* Platforms Affected: Jenkins LTS all versions equal to or lower than 2.426.3 Any operating system Any version |
Recommendation |
Upgrade to the latest version of Jenkins LTS (2.426.3 or later), available from the Jenkins Software Foundation download site, https://jenkins.io/download |
Related URL |
CVE-2024-23897,CVE-2024-23898 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|