CVE-2024-23897KEV · OVERDUE

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Critical · published January 24, 2024

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

727
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 An unauthenticated user can read ANY file on your Jenkins server just by sending a crafty command! This vulnerability is absolutely devastating! 🔥 Think of Jenkins like a bustling library where anyone can borrow a book without showing ID. Now imagine someone discovers a loophole that lets them read any book on the shelf, including all the secret documents hidden away in the archives—yikes! An attacker could easily exploit this flaw to access sensitive configuration files, user data, and even secrets that should remain locked away. This could lead to unauthorized access to your systems, exposing critical information and putting your entire infrastructure at risk—definitely not the kind of thing you want!

Put simply

Think of Jenkins like a bustling library where anyone can borrow a book without showing ID. Now imagine someone discovers a loophole that lets them read any book on the shelf, including all the secret documents hidden away in the archives—yikes! Jenkins versions 2.441 and earlier, as well as LTS 2.426.2 and earlier, fail to disable a feature in the CLI command parser that substitutes an '@' character followed by a file path with the file's contents, allowing for file reading without authentication.

What to do

An attacker could easily exploit this flaw to access sensitive configuration files, user data, and even secrets that should remain locked away. This could lead to unauthorized access to your systems, exposing critical information and putting your entire infrastructure at risk—definitely not the kind of thing you want! Immediately update Jenkins to version 2.442 or LTS 2.426.3 to patch this vulnerability. Additionally, review your access controls and ensure sensitive files are adequately protected. Don’t forget to monitor for any suspicious activity! You’ve got this! Follow these steps and you’ll have your Jenkins server secured in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Published
2024-01-24T17:52Z
KEV added
2024-08-19 · due 2024-09-09
EPSS history
Timeline
  • 19 AUG 00:00Z
    Added to CISA KEV — remediate by Sep 9
    kev
  • 24 JAN 17:52Z
    Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path…
    cvelistv5