Critical RCE Vulnerability in Jenkins Plugins
An unauthenticated arbitrary file read vulnerability through the CLI could lead to Remote Code Execution on Jenkins servers
Summary
An unauthenticated arbitrary file read vulnerability through the CLI could lead to Remote Code Execution on Jenkins servers
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Jenkins has released a security advisory to address a critical unauthenticated arbitrary file read vulnerability through the Jenkins CLI with a CVSSv3 score of 9.8. Attackers could exploit this vulnerability to read arbitrary files on the Jenkins controller file system using the default character encoding of the Jenkins controller process.
This vulnerability can be used to read cryptographic keys from binary files which could lead to a number of outcomes including remote code execution (RCE).
Exploitation of CVE-2024-23897 in the wild
Active exploitation of CVE-2024-23897 has been reported following the release of a public proof-of-concept.
Remediation advice
Affected organisations are encouraged to review the Jenkins Security Advisory and apply the necessary updates.
Definitive source of threat updates
Last edited: 29 January 2024 3:53 pm