Intel

AIKIDO-2026-984239

jenkins-core is vulnerable to Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)CVE-2026-84649 Published Yesterday

88

High Risk

This Affects:

JAVAjenkins-core
2.447 - 2.568.2
Fixed in 2.568.3
2.569 - 2.579
Fixed in 2.580
Are you affected? Scan for Free

TL;DR

An HTTP endpoint that serves dynamically generated JavaScript embeds the user's CSRF crumb as a string literal. An attacker who controls a page on the same site as Jenkins can read that crumb from the targeted user's session and perform actions on their behalf. The fix stops embedding the crumb as a string literal in those generated scripts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and an attacker can host content on the same site as Jenkins that a logged-in user may visit.

Background info

jenkins-core is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.447 - 2.568.2 and 2.569 - 2.579.

How to fix this

Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform