Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-23897

Quick assessment

Affected
Jenkins Project Jenkins
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Jenkins是Jenkins开源的一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。 Jenkins 2.441及之前版本、LTS 2.426.2及之前版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者读取Jenkins控制器文件系统。

AI Predicted 7.5 Difficulty: Easy KEV · Ransomware EPSS 100.00% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-23897

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Jenkins 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Jenkins是Jenkins开源的一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。 Jenkins 2.441及之前版本、LTS 2.426.2及之前版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者读取Jenkins控制器文件系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Jenkins Project Jenkins 0 ~ 1.606 -

II. Public POCs for CVE-2024-23897

# POC Description Source Link Shenlong Link
1 Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898 https://github.com/jenkinsci-cert/SECURITY-3314-3315 POC Details
2 CVE-2024-23897 (CVSS 9.8): Critical Jenkins Security Vulnerability, RCE POC https://github.com/forsaken0127/CVE-2024-23897 POC Details
3 None https://github.com/binganao/CVE-2024-23897 POC Details
4 CVE-2024-23897 https://github.com/h4x0r-dz/CVE-2024-23897 POC Details
5 CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner. https://github.com/xaitax/CVE-2024-23897 POC Details
6 None https://github.com/vmtyan/poc-cve-2024-23897 POC Details
7 Scanner for CVE-2024-23897 - Jenkins https://github.com/yoryio/CVE-2024-23897 POC Details
8 CVE-2024-23897 jenkins-cli https://github.com/CKevens/CVE-2024-23897 POC Details
9 on this git you can find all information on the CVE-2024-23897 https://github.com/iota4/PoC-jenkins-rce_CVE-2024-23897 POC Details
10 CVE-2024-23897 - Jenkins 任意文件读取 利用工具 https://github.com/wjlin0/CVE-2024-23897 POC Details
11 This repository presents a proof-of-concept of CVE-2024-23897 https://github.com/Vozec/CVE-2024-23897 POC Details
12 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. https://github.com/raheel0x01/CVE-2024-23897 POC Details
13 Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE https://github.com/viszsec/CVE-2024-23897 POC Details
14 None https://github.com/jopraveen/CVE-2024-23897 POC Details
15 PoC for CVE-2024-23897 https://github.com/AbraXa5/Jenkins-CVE-2024-23897 POC Details
16 on this git you can find all information on the CVE-2024-23897 https://github.com/iota4/PoC-Fix-jenkins-rce_CVE-2024-23897 POC Details
17 CVE-2024-23897 jenkins arbitrary file read which leads to unauthenticated RCE https://github.com/brijne/CVE-2024-23897-RCE POC Details
18 None https://github.com/WLXQqwer/Jenkins-CVE-2024-23897- POC Details
19 Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability) https://github.com/kaanatmacaa/CVE-2024-23897 POC Details
20 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. https://github.com/Praison001/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability POC Details
21 on this git you can find all information on the CVE-2024-23897 https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897 POC Details
22 CVE-2024-23897 https://github.com/B4CK4TT4CK/CVE-2024-23897 POC Details
23 None https://github.com/abdomagdy0/CVE-2024-23897-htb POC Details
24 POC for CVE-2024-23897 Jenkins File-Read https://github.com/godylockz/CVE-2024-23897 POC Details
25 Jenkins Arbitrary File Leak Vulnerability [CVE-2024-23897] https://github.com/ifconfig-me/CVE-2024-23897 POC Details
26 Perform with massive Jenkins Reading-2-RCE https://github.com/ThatNotEasy/CVE-2024-23897 POC Details
27 Un script realizado en python para atumatizar la vulnerabilidad CVE-2024-23897 https://github.com/pulentoski/CVE-2024-23897-Arbitrary-file-read POC Details
28 Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins. https://github.com/Nebian/CVE-2024-23897 POC Details
29 This is an exploit script for CVE-2024-23897, a vulnerability affecting certain systems. The script is intended for educational and testing purposes only. Ensure that you have the necessary permissions before using it. https://github.com/Abo5/CVE-2024-23897 POC Details
30 None https://github.com/TheRedDevil1/CVE-2024-23897 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-23897

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-23897 (1)

Exploits & Public PoCs for CVE-2024-23897 (2)

Mailing List Discussions for CVE-2024-23897 (1)

Security Blog Posts for CVE-2024-23897 (1)

Same Patch Batch · Jenkins Project · 2024-01-24 · 9 CVEs total

CVE-2024-23905 Jenkins Plugin Red Hat Dependency Analytics 安全漏洞
CVE-2024-23903 Jenkins Plugin GitLab Branch Source 安全漏洞
CVE-2024-23904 Jenkins Plugin Log Command 安全漏洞
CVE-2024-23902 Jenkins Plugin GitLab Branch Source 安全漏洞
CVE-2024-23900 Jenkins Plugin Matrix Project 安全漏洞
CVE-2024-23901 Jenkins Plugin GitLab Branch Source 安全漏洞
CVE-2024-23899 Jenkins Plugin Git server 安全漏洞
CVE-2024-23898 Jenkins 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2024-23897

No comments yet


Leave a comment