QID 996899

Date Published: 2024-02-05

QID 996899: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-53ph-2r2x-vqw8)

Jenkins has a built-in command line interface (CLI) to access Jenkins from a script or shell environment. Since Jenkins 2.217 and LTS 2.222.1, one of the ways to communicate with the CLI is through a WebSocket endpoint. This endpoint relies on the default Jenkins web request authentication functionality, like HTTP Basic authentication with API tokens, or session cookies. This endpoint is enabled when running on a version of Jetty for which Jenkins supports WebSockets. This is the case when using the provided native installers, packages, or the Docker containers, as well as when running Jenkins with the command java -jar jenkins.war.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-53ph-2r2x-vqw8 for updates and patch information.
    Vendor References

    CVEs related to QID 996899

    Software Advisories
    Advisory ID Software Component Link
    GHSA-53ph-2r2x-vqw8 org.jenkins-ci.main:jenkins-core URL Logo github.com/advisories/GHSA-53ph-2r2x-vqw8