CVE-2024-23898

A flaw was found in Jenkins where websocket access to the CLI does not perform origin validation of requests when they are made through the websocket...Read More ...

Continue Reading
FreeBSD : jenkins — multiple vulnerabilities (8b03d274-56ca-489e-821a-cf32f07643f0)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 8b03d274-56ca-489e-821a-cf32f07643f0 advisor ...

Continue Reading
Jenkins LTS < 2.426.3 / Jenkins weekly < 2.442 Multiple Vulnerabilities

According to its its self-reported version number, the version of Jenkins running on the remote web server is Jenkins LTS prior to 2.426.3 or Jenkins weekly prior to 2.442. It is, therefore, affected ...

Continue Reading
jenkins — multiple vulnerabilities

Jenkins Security Advisory: Description (Critical) SECURITY-3314 / CVE-2024-23897 Arbitrary file read vulnerability through the CLI can lead to RCE Description (High) SECURITY-3315 / CVE-2024-23898 Cro ...

Continue Reading
CVE-2024-23898

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross- ...

Continue Reading
tRPC vs GraphQL

Deciphering the Cloud Conundrum: An Introduction to tRPC &amp; GraphQL The dynamic domain of cloud technology presents a couple of instrumental methodologies in the arena of APIs: tRPC and GraphQL ...

Continue Reading
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface

SurrealDB depends on the tungstenite and tokio-tungstenite crates used by the axum crate, which handles connections to the SurrealDB WebSocket interface. On versions before 0.20.1, the tungstenite cra ...

Continue Reading
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface

SurrealDB depends on the tungstenite and tokio-tungstenite crates used by the axum crate, which handles connections to the SurrealDB WebSocket interface. On versions before 0.20.1, the tungstenite cra ...

Continue Reading

Back to Main

Subscribe for the latest news: