目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-23897 PoC — Jenkins 安全漏洞

来源
关联漏洞
标题: Jenkins 安全漏洞 (CVE-2024-23897)
Description:Jenkins是Jenkins开源的一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。 Jenkins 2.441及之前版本、LTS 2.426.2及之前版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者读取Jenkins控制器文件系统。
Description
Scanner for CVE-2024-23897 - Jenkins
介绍
# CVE-2024-23897

### CVE-2024-23897 - Arbitrary file read vulnerability through the CLI can lead to RCE

![image](https://github.com/yoryio/CVE-2024-23897/assets/134471901/cb2af884-9607-4e67-be70-447699d51ce8)


*Products and Versions affected:*

| Product                           | Affected Versions                                        |
| :-------------------------------- | :------------------------------------------------------- |
| Jenkis Server | <= 2.441 <br /> <= LTS 2.426.3|

- **CVSS:** CRITICAL
- **Actively Exploited:** [YES](https://www.helpnetsecurity.com/2024/01/29/cve-2024-23897/)
- **Patch:** [YES](https://www.jenkins.io/security/advisory/2024-01-24/)
- **Mitigation:** [YES](https://github.com/jenkinsci-cert/SECURITY-3314-3315/)

# Help

```
usage: CVE-2024-23897.py [-h] -c COUNTRY

options:
  -h, --help            show this help message and exit
  -c COUNTRY, --country COUNTRY
                        Country to scan with Shodan

```
**Example:** `python CVE-2024-23897.py -c US`

# Lab

You can use the Jenkin's Docker container with a specific vulnerable version:

```
docker pull jenkins/jenkins:2.414.3-jdk17
```

# Global Jenkins Servers with Shodan:

- **Shodan query:**
```
http.favicon.hash:81586312
```

![Screenshot from 2024-01-26 23-07-40](https://github.com/yoryio/CVE-2024-23897/assets/134471901/97ed0259-32b3-43cf-aefc-d71853fefffd)


# References

- [Jenkins Security Advisory 2024-01-24](https://www.jenkins.io/security/advisory/2024-01-24/)
- [Excessive Expansion: Uncovering Critical Security Vulnerabilities in Jenkins](https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/)
- [Breaking Down CVE-2024-23897: PoC Code Surfaces Just After Jenkins Advisory](https://securityonline.info/breaking-down-cve-2024-23897-poc-code-surfaces-just-after-jenkins-advisory/)
- [Allegedly active exploitation](https://twitter.com/shoucccc/status/1750601321831633026)
- [Critical Jenkins RCE flaw exploited in the wild. Patch now! (CVE-2024-23897)](https://www.helpnetsecurity.com/2024/01/29/cve-2024-23897/)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →