CVE-2024-23897
Jenkins Command Line Interface (CLI): Path Traversal
As of , CVE-2024-23897 in Jenkins Command Line Interface (CLI) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 19 August 2024
- US federal deadline
- 9 September 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Known
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.96 on 19 August 2024EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module and 1 Exploit-DB entry
- Fix
- Vendor advice: www.jenkins.ioLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
CISA's description
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
The CVE record's description, from jenkins
- CVE published
- 24 January 2024
- Assigned by
- jenkins
- CVSS
- 9.8 Critical (CVSS 3.1, from CISA-ADP)
- CWE-27
- Path Traversal: 'dir/../../filename'
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 51993).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Jenkins cli Ampersand Replacement Arbitrary File Readauxiliary module, rank normal
- Exploit-DB: Jenkins 2.441 - Local File InclusionEDB-ID 51993, 15 April 2024
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org