Database/Control plane, storage & DevOps
Jenkins: No origin validation on the CLI WebSocket endpoint
CVSS 8.8CVE-2024-23898Control plane, storage & DevOpscurated
Impact
No origin validation on the CLI WebSocket endpoint -> cross-site WebSocket hijacking, attacker runs CLI commands
Who can reach it
Network (remote)
What to do
Control-plane: same patch window as CVE-2024-23897
References
Related entries
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- Jenkins: CLI parser expands `@file` into argument contentsCVE-2024-23897 · JenkinsCritical
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`CVE-2024-24747 · MinIOHigh
- Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway pluginCVE-2024-24909 · Dell OpenManage Integration with Microsoft Windows Admin Center (gateway plugin)High
- A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewCVE-2024-30368 · A10 Thunder ADC (CsrRequestView)High
- CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesCVE-2024-31856 · CyberPower PowerPanel MQTT message handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.