CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 23, 2024
- Published Date
- January 24, 2024
- Last Updated
- August 19, 2024
- Vendor
- Jenkins Project
- Product
- Jenkins
- Description
- Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-08-19 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2024/CVE-2024-23897.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
verylazytech/CVE-2024-23897
Type: github • Created: 2024-09-30 16:38:28 UTC • Stars: 8
Maalfer/CVE-2024-23897
Type: github • Created: 2024-05-16 09:32:51 UTC • Stars: 8
mil4ne/CVE-2024-23897-Jenkins-4.441
Type: github • Created: 2024-05-08 02:28:46 UTC • Stars: 5
ThatNotEasy/CVE-2024-23897
Type: github • Created: 2024-02-19 02:29:12 UTC • Stars: 2
godylockz/CVE-2024-23897
Type: github • Created: 2024-02-16 07:16:04 UTC • Stars: 26
Praison001/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability
Type: github • Created: 2024-02-07 15:07:37 UTC • Stars: 3
kaanatmacaa/CVE-2024-23897
Type: github • Created: 2024-02-04 20:56:42 UTC • Stars: 18
viszsec/CVE-2024-23897
Type: github • Created: 2024-01-29 04:41:53 UTC • Stars: 5
Vozec/CVE-2024-23897
Type: github • Created: 2024-01-28 01:57:06 UTC • Stars: 16
wjlin0/CVE-2024-23897
Type: github • Created: 2024-01-27 19:34:48 UTC • Stars: 78
10T4/PoC-Fix-jenkins-rce_CVE-2024-23897
Type: github • Created: 2024-01-27 13:27:57 UTC • Stars: 5
AiK1d/CVE-2024-23897
Type: github • Created: 2024-01-27 12:57:28 UTC • Stars: 15
yoryio/CVE-2024-23897
Type: github • Created: 2024-01-27 04:35:20 UTC • Stars: 2
xaitax/CVE-2024-23897
Type: github • Created: 2024-01-26 19:00:03 UTC • Stars: 73
h4x0r-dz/CVE-2024-23897
Type: github • Created: 2024-01-26 09:44:32 UTC • Stars: 198
binganao/CVE-2024-23897
Type: github • Created: 2024-01-26 08:02:00 UTC • Stars: 100