logo

Critical Jenkins Vulnerability Exposes Servers to RCE Attacks - Patch ASAP!

ID: 2efd6d87-01e7-5a9f-8db8-dee658a2f03b

STIX ID: report--2efd6d87-01e7-5a9f-8db8-dee658a2f03b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Jenkins maintainers fixed CVE-2024-23897, an arbitrary file read flaw in the args4j-based CLI expandAtFiles feature that is enabled by default; the issue can expose files (including some binary secrets) and be chained to achieve remote code execution and other severe impacts. The vulnerability was reported by a researcher, patched in Jenkins 2.442 / LTS 2.426.3, short-term mitigation is to disable CLI access, and proof-of-concept exploit code has been published publicly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.