CVE-2024-23897

Published Jan 24, 2024

Last updated 2 months ago

Overview

Description
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
Source
jenkinsci-cert@googlegroups.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Exploit added on
Aug 19, 2024
Exploit action due
Sep 9, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-22
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-27

Social media

Hype score
Not currently trending
  1. Bitsight TRACE researchers tackled CVE-2024-23897 with a systematic, non-intrusive detection method—going beyond version checks to confirm vulnerabilities with confidence. Cybersecurity research done right. Read more: https://t.co/9gSdmCsTN4 #BitsightTRACE #ThreatIntel https:/

    @Bitsight

    4 Feb 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. The CVE-2024-23897 vulnerability is interesting, I was testing it. 💻🤖👾 https://t.co/ErLdQrhP6j

    @HckSystem94_

    17 Jan 2025

    105 Impressions

    0 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Exploiting Jenkins + CVE-2024-23897 https://t.co/gvvYybKj9C https://t.co/33lMTtbjXs

    @jaacostan

    7 Jan 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. How do attackers exploit Jenkins CVE-2024-23897? Using tools like Shodan and CLI, they target outdated systems. Learn how to defend your infrastructure: https://t.co/U7lsLMTi5l #Jenkins #vulnerability https://t.co/tS9Lqj6p7a

    @FireCompass

    6 Dec 2024

    15 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Critical alert for Jenkins users! CVE-2024-23897, a dangerous RCE flaw, allows attackers to access sensitive files on your servers. Stay informed, stay secure. Learn more: https://t.co/U7lsLMTPUT #Jenkins #cybersecurityawareness https://t.co/I7zYkENHtX

    @FireCompass

    2 Dec 2024

    37 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. https://t.co/gmlyMf3MhG Jenkins-Args4j-CVE-2024-23897-POC #github #exploit

    @ksg93rd

    11 Nov 2024

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Jenkins has disclosed a critical RCE vulnerability (CVE-2024-23897) affecting its CLI with a CVSS score of 9.8. #Cybersecurity #Jenkins #RCE #CVE2024 #DevOps #AppSec #Vulnerability https://t.co/9Uw1UEDJYS

    @defhawk_specter

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations