« Back to list

CVE-2024-23897

Status: AnalyzedCritical (9.8)⚠ Active exploitation💥 Exploit

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

CISA KEV — actively exploited

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Vulnerabilidad crítica en parser CLI de Jenkins accesible sin autenticación (AV:N, PR:N) permitiendo lectura de archivos arbitrarios mediante '@' + ruta; impacto de exfiltración de datos sensibles del sistema de archivos del controlador.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-23897",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-23897",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-19T15:35:31.038735Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins Project",
          "product": "Jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "1.606",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.442",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.426.3",
              "lessThan": "2.426.*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.440.1",
              "lessThan": "2.440.*",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*"
          ],
          "vendor": "jenkins",
          "product": "jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "1.606",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.442",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.426.3",
              "lessThan": "2.427",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.440.1",
              "lessThan": "2.441",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*"
          ],
          "vendor": "jenkins",
          "product": "jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "1.606",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.442",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.426.3",
              "lessThan": "2.427",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.440.1",
              "lessThan": "2.441",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*"
          ],
          "vendor": "jenkins",
          "product": "jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "1.606",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.442",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.426.3",
              "lessThan": "2.427",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.440.1",
              "lessThan": "2.441",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*"
          ],
          "vendor": "jenkins",
          "product": "jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "1.606",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.442",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.426.3",
              "lessThan": "2.427",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.440.1",
              "lessThan": "2.441",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-01-24T18:15:09.370",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/176839/Jenkins-2.441-LTS-2.426.3-CVE-2024-23897-Scanner.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/176840/Jenkins-2.441-LTS-2.426.3-Arbitrary-File-Read.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6",
      "tags": [
        "Mailing List"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/",
      "tags": [
        "Exploit",
        "Press/Media Coverage"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/176839/Jenkins-2.441-LTS-2.426.3-CVE-2024-23897-Scanner.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/176840/Jenkins-2.441-LTS-2.426.3-Arbitrary-File-Read.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/01/24/6",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/",
      "tags": [
        "Exploit",
        "Press/Media Coverage"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.vicarius.io/vsociety/posts/the-anatomy-of-a-jenkins-vulnerability-cve-2024-23897-revealed-1",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23897",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-27"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system."
    },
    {
      "lang": "es",
      "value": "Jenkins 2.441 y anteriores, LTS 2.426.2 y anteriores no desactivan una función de su analizador de comandos CLI que reemplaza un carácter '@' seguido de una ruta de archivo en un argumento con el contenido del archivo, lo que permite a atacantes no autenticados leer archivos arbitrarios en el sistema de archivos del controlador Jenkins."
    }
  ],
  "lastModified": "2026-06-17T07:13:49.330",
  "cisaActionDue": "2024-09-09",
  "cisaExploitAdd": "2024-08-19",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "669379F5-5F67-4002-AD76-F8C470C89D61",
              "versionEndExcluding": "2.426.3"
            },
            {
              "criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "493B263C-C8C7-4741-B7F8-B672E86CC8B4",
              "versionEndExcluding": "2.442"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com",
  "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Jenkins Command Line Interface (CLI) Path Traversal Vulnerability"
}