Critical, Actively Exploited Jenkins RCE Bug Suffers Patch Lag
ID: ad072765-78b6-5624-b1b1-f0d4ae9a58b5
STIX ID: report--ad072765-78b6-5624-b1b1-f0d4ae9a58b5
Feed Name: Dark Reading
A critical Jenkins CLI path traversal vulnerability (CVE-2024-23897, CVSS 9.8) remains actively exploited months after disclosure; despite a security fix, many instances remained unpatched, with public PoCs and automated attacks emerging quickly. Exploitation has led to credential theft, corporate GitHub breaches, source-code exfiltration, and ransomware (including RansomExx) incidents, affecting tens of thousands of exposed Jenkins installations and prompting CISA KEV listing and remediation urgency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
