Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released
ID: de4faa0c-9cd5-54d0-9e0a-d5c478b1d81f
STIX ID: report--de4faa0c-9cd5-54d0-9e0a-d5c478b1d81f
Feed Name: The Register (Security)
A critical Jenkins vulnerability (CVE-2024-23897, CVSS 9.8) affecting the built-in CLI’s expandAtFiles feature exposes roughly 45,000 public Jenkins instances worldwide and can be used to read arbitrary files — potentially leaking SSH keys, credentials, source code, and build artifacts; public proof-of-concept exploits were released days after disclosure, and administrators are urged to patch or disable the CLI and review access settings to prevent unauthenticated file reads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
