logo

Exposing the Exploitation: How CVE-2024-23897 Led to the Compromise of Github Repos via Jenkins LFI Vulnerability

ID: c6e65097-6dc4-540f-93a5-2614343353d2

STIX ID: report--c6e65097-6dc4-540f-93a5-2614343353d2

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2024-07-29

Date Updated: 2026-04-27

...
...

This report analyzes CVE-2024-23897, an unauthenticated Local File Inclusion vulnerability in Jenkins (affecting Jenkins 2.441 and earlier, LTS 2.426.2 and earlier) that IntelBroker exploited to read credentials.xml, decrypt stored GitHub SSH keys and tokens via the Jenkins Script Console, and exfiltrate private repositories; the document includes Docker reproduction steps, PoC usage, example commands, and mitigation recommendations such as timely patching, strong authentication, and least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.