KEVIntel
9.8
CVSS
Critical

CVE-2024-23897

PUBLISHED

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by...

Exploited in the wild Used in malware PoC available Remote Low complexity No user interaction
Vendor
Jenkins Project
Product
Jenkins
Published
Jan 24, 2024
EPSS

Description

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

windows cisa malware ransomware nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-08-19 00:00:00 UTC · Source

Used in malware

Recorded 2024-08-19 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-01-27 19:34:48 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Aug 19, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

verylazytech/CVE-2024-23897

github · Created 2024-09-30 16:38:28 UTC · 8 stars

POC - Jenkins File Read Vulnerability - CVE-2024-23897

Maalfer/CVE-2024-23897

github · Created 2024-05-16 09:32:51 UTC · 8 stars

Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados

mil4ne/CVE-2024-23897-Jenkins-4.441

github · Created 2024-05-08 02:28:46 UTC · 5 stars

ThatNotEasy/CVE-2024-23897

github · Created 2024-02-19 02:29:12 UTC · 2 stars

Perform with massive Jenkins Reading-2-RCE

godylockz/CVE-2024-23897

github · Created 2024-02-16 07:16:04 UTC · 26 stars

POC for CVE-2024-23897 Jenkins File-Read

Praison001/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

github · Created 2024-02-07 15:07:37 UTC · 3 stars

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

kaanatmacaa/CVE-2024-23897

github · Created 2024-02-04 20:56:42 UTC · 18 stars

Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)

viszsec/CVE-2024-23897

github · Created 2024-01-29 04:41:53 UTC · 5 stars

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

Vozec/CVE-2024-23897

github · Created 2024-01-28 01:57:06 UTC · 16 stars

This repository presents a proof-of-concept of CVE-2024-23897

wjlin0/CVE-2024-23897

github · Created 2024-01-27 19:34:48 UTC · 78 stars

CVE-2024-23897 - Jenkins 任意文件读取 利用工具

10T4/PoC-Fix-jenkins-rce_CVE-2024-23897

github · Created 2024-01-27 13:27:57 UTC · 5 stars

on this git you can find all information on the CVE-2024-23897

AiK1d/CVE-2024-23897

github · Created 2024-01-27 12:57:28 UTC · 15 stars

CVE-2024-23897 jenkins-cli

yoryio/CVE-2024-23897

github · Created 2024-01-27 04:35:20 UTC · 2 stars

Scanner for CVE-2024-23897 - Jenkins

xaitax/CVE-2024-23897

github · Created 2024-01-26 19:00:03 UTC · 73 stars

CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.

h4x0r-dz/CVE-2024-23897

github · Created 2024-01-26 09:44:32 UTC · 198 stars

CVE-2024-23897

binganao/CVE-2024-23897

github · Created 2024-01-26 08:02:00 UTC · 100 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nessus

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei