CVE-2024-23897
ID: 73f4c184-f376-5fa4-93f0-4374302601fb
STIX ID: report--73f4c184-f376-5fa4-93f0-4374302601fb
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes a Jenkins vulnerability in args4j where CLI arguments beginning with '@' are interpreted as file inclusions, allowing attackers to read arbitrary files from the Jenkins controller; the issue is exacerbated by insecure settings (Allow users to register, Enable anonymous read permission) and can be exploited via jenkins-cli.jar or crafted POST requests to /cli?remoting=false to exfiltrate file contents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
