BIT-jenkins-2026-33002

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jenkins/BIT-jenkins-2026-33002.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-jenkins-2026-33002
Aliases
Published
2026-03-20T09:15:13.235Z
Modified
2026-03-20T10:11:00.475911Z
Summary
[none]
Details

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.

Database specific
{
    "cpes": [
        "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:maven:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / jenkins

Package

Name
jenkins
Purl
pkg:bitnami/jenkins

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.426.3
Fixed
2.555.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jenkins/BIT-jenkins-2026-33002.json"