logo

Fix Available for Critical Jenkins Flaw That Leads to RCE Attacks

ID: 0388f0ef-1e65-5419-b225-b4718320a217

STIX ID: report--0388f0ef-1e65-5419-b225-b4718320a217

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2024-01-29

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Researchers disclosed two Jenkins vulnerabilities: CVE-2024-23897 allows unauthenticated arbitrary file reads via the args4j expandAtFiles feature (which can expose binary keys and enable RCE chains), and CVE-2024-23898 is a high-severity cross-site WebSocket hijacking flaw that can allow execution of arbitrary CLI commands; both flaws are fixed in Jenkins 2.442 and LTS 2.426.3 with workarounds provided for users who cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.