Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314
http://packetstormsecurity.com/files/176839/Jenkins-2.441-LTS-2.426.3-CVE-2024-23897-Scanner.html
https://github.com/chengbochuan3/Security-Blog
https://github.com/chengbochuan3/CVE-CICD-Security
https://github.com/chengbochuan3/CVE-Learn
https://github.com/nkoziel/cve-to-detection-rule
https://github.com/hhhell/CVE-Vulnerability-Reproduction
https://github.com/razureink/cve-2024-23897-jenkins_lfi_reproduction
https://github.com/Dungsocool/CVE-2024-23897
https://github.com/godly-raam/CVE-Research-Portfolio
https://github.com/ykrishhh/cve-pocs
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/reloading01/threat-intelligence-dataset
https://github.com/av4nth1ka/cve-research-agent
https://github.com/1392081456/sigma-detection-rules
https://github.com/h0mi3e/THANOS
https://github.com/1392081456/ctf-notes
https://github.com/DiegoRodriguez-GL/bigschool-ciberseguridad
https://github.com/w41l3r/jenkins_scan
https://github.com/phantom-offensive/AppAssault
https://github.com/phantom-offensive/AppAssaultLab
https://github.com/Phantom-C2-77/AppAssaultLab
https://github.com/hermestoola/bb-hunter-pro
https://github.com/vmc8ll/poc-CVE-2024-23897
https://github.com/Npg-1/CVE_Website
https://github.com/Pocland-db/cve-pocs
https://github.com/digenaldo/daedalus
https://github.com/harekrishnarai/CVE-2024-23897-test-windows
https://github.com/aadi0258/Exploit-CVE-2024-23897
https://github.com/hybinn/CVE-2024-23897
https://github.com/amalpvatayam67/day03-jenkins-23897
https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic
https://github.com/Fineken/Jenkins-CVE-2024-23897-Lab
https://github.com/ismailmazumder/SL7CVELabsBuilder
https://github.com/securelayer7/SL7CVELabsBuilder
https://github.com/tvasari/CVE-2024-23897
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
https://github.com/slytechroot/CVE-2024-23897
https://github.com/D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
https://github.com/safeer-accuknox/Jenkins-Args4j-CVE-2024-23897-POC
https://github.com/zgimszhd61/CVE-2024-23897-poc
https://github.com/ShieldAuth-PHP/PBL05-CVE-Analsys
https://github.com/BinaryGoodBoy0101/Jenkins-Exploit-CVE-2024-23897-Fsociety
https://github.com/i-100-user/CVE-2024-25897
https://github.com/NoSpaceAvailable/CVE-2024-23897
https://github.com/Athulya666/CVE-2024-23897
https://github.com/Pr0t0c01/CVEs
https://github.com/ifconfig-me/CVE-2024-23897
https://github.com/B4CK4TT4CK/CVE-2024-23897
https://github.com/kaanatmacaa/CVE-2024-23897
https://github.com/EvilGreys/CVE
https://github.com/wjlin0/CVE-2024-23897
https://github.com/iota4/PoC-Fix-jenkins-rce_CVE-2024-23897
https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897
https://github.com/CKevens/CVE-2024-23897
https://github.com/jenkinsci-cert/SECURITY-3314-3315
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23897
http://www.openwall.com/lists/oss-security/2024/01/24/6
http://packetstormsecurity.com/files/176840/Jenkins-2.441-LTS-2.426.3-Arbitrary-File-Read.html
Published: 2024-01-24
Updated: 2025-10-24
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.99999
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest