logo

Critical Jenkins Vulnerability Let Attackers Execute Remote Code

ID: 6eda67e8-2eb8-5cb9-a4a9-bde51102dea2

STIX ID: report--6eda67e8-2eb8-5cb9-a4a9-bde51102dea2

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2024-01-26

Date Updated: 2026-04-21

Author: Guru

...
...

A critical Jenkins CLI parser vulnerability (CVE-2024-23897, CVSS 9.8) in versions 2.441 and earlier enables arbitrary file reads and can lead to remote code execution; attackers may read cryptographic keys, decrypt secrets, delete items, and download Java heap dumps. The report also lists additional related CVEs, notes a fix in Jenkins 2.442/LTS 2.426.3 that disables the parser, and recommends updating or blocking CLI access as a workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.