Skip to main content

Critical RCE Vulnerability in Jenkins Plugins

An unauthenticated arbitrary file read vulnerability through the CLI could lead to Remote Code Execution on Jenkins servers

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

An unauthenticated arbitrary file read vulnerability through the CLI could lead to Remote Code Execution on Jenkins servers


Threat details

Introduction

Jenkins has released a security advisory to address a critical unauthenticated arbitrary file read vulnerability through the Jenkins CLI with a CVSSv3 score of 9.8. Attackers could exploit this vulnerability to read arbitrary files on the Jenkins controller file system using the default character encoding of the Jenkins controller process.

This vulnerability can be used to read cryptographic keys from binary files which could lead to a number of outcomes including remote code execution (RCE).

Exploitation of CVE-2024-23897 in the wild

Active exploitation of CVE-2024-23897 has been reported following the release of a public proof-of-concept.


Remediation advice

Affected organisations are encouraged to review the Jenkins Security Advisory and apply the necessary updates.


Definitive source of threat updates


Last edited: 29 January 2024 3:53 pm