logo

Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released

ID: de4faa0c-9cd5-54d0-9e0a-d5c478b1d81f

STIX ID: report--de4faa0c-9cd5-54d0-9e0a-d5c478b1d81f

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-01-30

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A critical Jenkins vulnerability (CVE-2024-23897, CVSS 9.8) affecting the built-in CLI’s expandAtFiles feature exposes roughly 45,000 public Jenkins instances worldwide and can be used to read arbitrary files — potentially leaking SSH keys, credentials, source code, and build artifacts; public proof-of-concept exploits were released days after disclosure, and administrators are urged to patch or disable the CLI and review access settings to prevent unauthenticated file reads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.