Advisory 49

Advisory 49 : Jenkins Vulnerability Advisory

Release Date : 24th of January 2024

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.

What is it?

These are Multiple vulnerabilities affecting Jenkins products which could result in Remote Code Execution and Cross-site webSocket hijacking.

CVE-2024-23897 refers to a Critical Vulnerability in the command line interface command parser allowing attackers to read arbitrary files on the Jenkins controller file system, resulting in possible Remote Code Execution.

CVE-2024-23898 refers to a High vulnerability which enables cross-site WebSocket Hijacking in the command line interface, resulting in the potential threat actors to execute CLI command on the Jenkins controller.

References

  1. https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/multiple-vulnerabilities-jenkins-products
  2. https://www.jenkins.io/security/advisory/2024-01-24/
  3. https://nvd.nist.gov/vuln/detail/CVE-2024-23897