Executive brief
The Jenkins Command Line Interface (CLI) fails to disable a feature in its command parser that replaces an '@' character followed by a file path with the file's contents. This path traversal vulnerability allows unauthenticated attackers to read arbitrary files on the Jenkins controller file system, potentially leading to remote code execution.
Affected products
- Jenkins Project Jenkins up to 2.441
- Jenkins Project Jenkins LTS up to 2.426.2
Timeline
- 2024-01-24: disclosed: Vendor advisory SECURITY-3314 published.
- 2024-08-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-08-19: other: Vulnerability published to NVD.