Fix Available for Critical Jenkins Flaw That Leads to RCE Attacks
ID: 0388f0ef-1e65-5419-b225-b4718320a217
STIX ID: report--0388f0ef-1e65-5419-b225-b4718320a217
Feed Name: Security Boulevard
Threat Score
Researchers disclosed two Jenkins vulnerabilities: CVE-2024-23897 allows unauthenticated arbitrary file reads via the args4j expandAtFiles feature (which can expose binary keys and enable RCE chains), and CVE-2024-23898 is a high-severity cross-site WebSocket hijacking flaw that can allow execution of arbitrary CLI commands; both flaws are fixed in Jenkins 2.442 and LTS 2.426.3 with workarounds provided for users who cannot immediately upgrade.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
