Critical Jenkins Vulnerability Exposes Servers to RCE Attacks - Patch ASAP!
ID: 2efd6d87-01e7-5a9f-8db8-dee658a2f03b
STIX ID: report--2efd6d87-01e7-5a9f-8db8-dee658a2f03b
Feed Name: The Hacker News
Threat Score
Jenkins maintainers fixed CVE-2024-23897, an arbitrary file read flaw in the args4j-based CLI expandAtFiles feature that is enabled by default; the issue can expose files (including some binary secrets) and be chained to achieve remote code execution and other severe impacts. The vulnerability was reported by a researcher, patched in Jenkins 2.442 / LTS 2.426.3, short-term mitigation is to disable CLI access, and proof-of-concept exploit code has been published publicly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
