logo

Exploits released for critical Jenkins RCE flaw, patch now

ID: 52504ced-3d08-5797-b599-a308d8ffe591

STIX ID: report--52504ced-3d08-5797-b599-a308d8ffe591

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-01-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple proof-of-concept exploits for two critical Jenkins vulnerabilities (CVE-2024-23897 and CVE-2024-23898) have been published; CVE-2024-23897 allows unauthenticated arbitrary file reads (and can lead to RCE under certain conditions) via args4j argument expansion, while CVE-2024-23898 enables cross-site WebSocket hijacking to execute CLI commands. Researchers observed exploitation activity in honeypots and Jenkins issued patched releases (2.442 and LTS 2.426.3) and an advisory on 2024-01-24.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.