CVE-2024-23898 is a critical cross-site WebSocket hijacking (CSWSH) vulnerability affecting Jenkins versions 2.217 through 2.441 and LTS versions 2.222.1 through 2.426.2. This flaw, rated 8.8 HIGH, allows unauthenticated attackers to execute arbitrary CLI commands on the Jenkins controller due to a lack of origin validation on the CLI WebSocket endpoint. While not yet listed in CISA KEV, this vulnerability has high community discussion and media coverage, with public exploits available, indicating a significant risk of active exploitation. Organizations using affected Jenkins versions should prioritize patching immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.217, <= 2.441CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* | ||
>= 2.222.1, <= 2.426.2CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.