Jenkins是Jenkins开源的一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。 Jenkins 2.441及之前版本、LTS 2.426.2及之前版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者读取Jenkins控制器文件系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Jenkins Project | Jenkins | 0 ~ 1.606 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898 | https://github.com/jenkinsci-cert/SECURITY-3314-3315 | POC Details |
| 2 | CVE-2024-23897 (CVSS 9.8): Critical Jenkins Security Vulnerability, RCE POC | https://github.com/forsaken0127/CVE-2024-23897 | POC Details |
| 3 | None | https://github.com/binganao/CVE-2024-23897 | POC Details |
| 4 | CVE-2024-23897 | https://github.com/h4x0r-dz/CVE-2024-23897 | POC Details |
| 5 | CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner. | https://github.com/xaitax/CVE-2024-23897 | POC Details |
| 6 | None | https://github.com/vmtyan/poc-cve-2024-23897 | POC Details |
| 7 | Scanner for CVE-2024-23897 - Jenkins | https://github.com/yoryio/CVE-2024-23897 | POC Details |
| 8 | CVE-2024-23897 jenkins-cli | https://github.com/CKevens/CVE-2024-23897 | POC Details |
| 9 | on this git you can find all information on the CVE-2024-23897 | https://github.com/iota4/PoC-jenkins-rce_CVE-2024-23897 | POC Details |
| 10 | CVE-2024-23897 - Jenkins 任意文件读取 利用工具 | https://github.com/wjlin0/CVE-2024-23897 | POC Details |
| 11 | This repository presents a proof-of-concept of CVE-2024-23897 | https://github.com/Vozec/CVE-2024-23897 | POC Details |
| 12 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. | https://github.com/raheel0x01/CVE-2024-23897 | POC Details |
| 13 | Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE | https://github.com/viszsec/CVE-2024-23897 | POC Details |
| 14 | None | https://github.com/jopraveen/CVE-2024-23897 | POC Details |
| 15 | PoC for CVE-2024-23897 | https://github.com/AbraXa5/Jenkins-CVE-2024-23897 | POC Details |
| 16 | on this git you can find all information on the CVE-2024-23897 | https://github.com/iota4/PoC-Fix-jenkins-rce_CVE-2024-23897 | POC Details |
| 17 | CVE-2024-23897 jenkins arbitrary file read which leads to unauthenticated RCE | https://github.com/brijne/CVE-2024-23897-RCE | POC Details |
| 18 | None | https://github.com/WLXQqwer/Jenkins-CVE-2024-23897- | POC Details |
| 19 | Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability) | https://github.com/kaanatmacaa/CVE-2024-23897 | POC Details |
| 20 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. | https://github.com/Praison001/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability | POC Details |
| 21 | on this git you can find all information on the CVE-2024-23897 | https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897 | POC Details |
| 22 | CVE-2024-23897 | https://github.com/B4CK4TT4CK/CVE-2024-23897 | POC Details |
| 23 | None | https://github.com/abdomagdy0/CVE-2024-23897-htb | POC Details |
| 24 | POC for CVE-2024-23897 Jenkins File-Read | https://github.com/godylockz/CVE-2024-23897 | POC Details |
| 25 | Jenkins Arbitrary File Leak Vulnerability [CVE-2024-23897] | https://github.com/ifconfig-me/CVE-2024-23897 | POC Details |
| 26 | Perform with massive Jenkins Reading-2-RCE | https://github.com/ThatNotEasy/CVE-2024-23897 | POC Details |
| 27 | Un script realizado en python para atumatizar la vulnerabilidad CVE-2024-23897 | https://github.com/pulentoski/CVE-2024-23897-Arbitrary-file-read | POC Details |
| 28 | Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins. | https://github.com/Nebian/CVE-2024-23897 | POC Details |
| 29 | This is an exploit script for CVE-2024-23897, a vulnerability affecting certain systems. The script is intended for educational and testing purposes only. Ensure that you have the necessary permissions before using it. | https://github.com/Abo5/CVE-2024-23897 | POC Details |
| 30 | None | https://github.com/TheRedDevil1/CVE-2024-23897 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-23905 | Jenkins Plugin Red Hat Dependency Analytics 安全漏洞 | |
| CVE-2024-23903 | Jenkins Plugin GitLab Branch Source 安全漏洞 | |
| CVE-2024-23904 | Jenkins Plugin Log Command 安全漏洞 | |
| CVE-2024-23902 | Jenkins Plugin GitLab Branch Source 安全漏洞 | |
| CVE-2024-23900 | Jenkins Plugin Matrix Project 安全漏洞 | |
| CVE-2024-23901 | Jenkins Plugin GitLab Branch Source 安全漏洞 | |
| CVE-2024-23899 | Jenkins Plugin Git server 安全漏洞 | |
| CVE-2024-23898 | Jenkins 安全漏洞 |
No comments yet