Critical Jenkins Vulnerability Let Attackers Execute Remote Code
ID: 6eda67e8-2eb8-5cb9-a4a9-bde51102dea2
STIX ID: report--6eda67e8-2eb8-5cb9-a4a9-bde51102dea2
Feed Name: cybersecurityNews.com
Threat Score
A critical Jenkins CLI parser vulnerability (CVE-2024-23897, CVSS 9.8) in versions 2.441 and earlier enables arbitrary file reads and can lead to remote code execution; attackers may read cryptographic keys, decrypt secrets, delete items, and download Java heap dumps. The report also lists additional related CVEs, notes a fix in Jenkins 2.442/LTS 2.426.3 that disables the parser, and recommends updating or blocking CLI access as a workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
