QID 731286
Date Published: 2024-03-25
QID 731286: Jenkins Core Denial of Service (DoS) Vulnerability (SECURITY-3379 Jenkins Security Advisory 2024-03-20)
Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.
CVE-2024-22201: Jenkins 2.443 and earlier, LTS 2.440.1 and earlier bundles versions of Jetty affected by the security vulnerability. This vulnerability allows unauthenticated attackers to cause a denial of service.
Affected Versions:
Jenkins weekly up to and including 2.443.
Jenkins LTS up to and including 2.440.1.
Fixed Versions:
Jenkins weekly should be updated to version 2.444.
Jenkins LTS should be updated to version 2.440.2.
QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of Jenkins core from the HTTP response header.
Note: This QID is marked as Practice as the vulnerability has a workaround which, cannot be reliably detected in the detection.
A successful exploitation of this vulnerability may allows unauthenticated attackers to cause a denial of service.
For further details refer to SECURITY-3379 Jenkins Security Advisory 2024-03-20
Workaround:
Administrators unable to update to these releases of Jenkins (or newer) are advised to disable HTTP/2.
- Jenkins Security Advisory 2024-03-20 -
www.jenkins.io/security/advisory/2024-03-20/
CVEs related to QID 731286
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SECURITY-3379 Jenkins Security Advisory 2024-03-20 |
|