PT-2026-84772 · Jenkins+1 · Jenkins

CVE-2026-84649

·

Publicado

2026-09-02

·

Atualizado

2026-09-08

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In Stapler 1839.ved17667b a eb 5 through 2107.v8dfcb e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a 6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-JENKINS-2026-84649
CVE-2026-84649

Produtos afetados

Jenkins