CVE-2024-23897 is a critical vulnerability affecting Jenkins 2.441 and earlier, and LTS 2.426.2 and earlier, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system due to a CLI command parser feature. With a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited, including in ransomware campaigns, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.426.3CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
< 2.442CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.