Junglewise Threat Intelligence

CVE-2024-23897: Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

CVE-2024-23897 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-08-19

Vendors: Jenkins Project, Jenkins.

Executive brief

The Jenkins Command Line Interface (CLI) fails to disable a feature in its command parser that replaces an '@' character followed by a file path with the file's contents. This path traversal vulnerability allows unauthenticated attackers to read arbitrary files on the Jenkins controller file system, potentially leading to remote code execution.

Affected products

  • Jenkins Project Jenkins up to 2.441
  • Jenkins Project Jenkins LTS up to 2.426.2

Timeline

  • 2024-01-24: disclosed: Vendor advisory SECURITY-3314 published.
  • 2024-08-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-08-19: other: Vulnerability published to NVD.