logo

CVE-2024-23897

ID: 73f4c184-f376-5fa4-93f0-4374302601fb

STIX ID: report--73f4c184-f376-5fa4-93f0-4374302601fb

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a Jenkins vulnerability in args4j where CLI arguments beginning with '@' are interpreted as file inclusions, allowing attackers to read arbitrary files from the Jenkins controller; the issue is exacerbated by insecure settings (Allow users to register, Enable anonymous read permission) and can be exploited via jenkins-cli.jar or crafted POST requests to /cli?remoting=false to exfiltrate file contents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.