Exploits released for critical Jenkins RCE flaw, patch now
ID: 52504ced-3d08-5797-b599-a308d8ffe591
STIX ID: report--52504ced-3d08-5797-b599-a308d8ffe591
Feed Name: Bleeping Computer
Multiple proof-of-concept exploits for two critical Jenkins vulnerabilities (CVE-2024-23897 and CVE-2024-23898) have been published; CVE-2024-23897 allows unauthenticated arbitrary file reads (and can lead to RCE under certain conditions) via args4j argument expansion, while CVE-2024-23898 enables cross-site WebSocket hijacking to execute CLI commands. Researchers observed exploitation activity in honeypots and Jenkins issued patched releases (2.442 and LTS 2.426.3) and an advisory on 2024-01-24.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
