CVE-2024-23897

critical

Description

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

References

https://github.com/chengbochuan3/Security-Blog

https://github.com/chengbochuan3/CVE-CICD-Security

https://github.com/chengbochuan3/CVE-Learn

https://github.com/nkoziel/cve-to-detection-rule

https://github.com/hhhell/CVE-Vulnerability-Reproduction

https://github.com/razureink/cve-2024-23897-jenkins_lfi_reproduction

https://github.com/Dungsocool/CVE-2024-23897

https://github.com/godly-raam/CVE-Research-Portfolio

https://github.com/ykrishhh/cve-pocs

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/reloading01/threat-intelligence-dataset

https://github.com/av4nth1ka/cve-research-agent

https://github.com/1392081456/sigma-detection-rules

https://github.com/h0mi3e/THANOS

https://github.com/1392081456/ctf-notes

https://github.com/DiegoRodriguez-GL/bigschool-ciberseguridad

https://github.com/w41l3r/jenkins_scan

https://github.com/phantom-offensive/AppAssault

https://github.com/phantom-offensive/AppAssaultLab

https://github.com/Phantom-C2-77/AppAssaultLab

https://github.com/hermestoola/bb-hunter-pro

https://github.com/vmc8ll/poc-CVE-2024-23897

https://github.com/Npg-1/CVE_Website

https://github.com/Pocland-db/cve-pocs

https://github.com/digenaldo/daedalus

https://github.com/harekrishnarai/CVE-2024-23897-test-windows

https://github.com/aadi0258/Exploit-CVE-2024-23897

https://github.com/hybinn/CVE-2024-23897

https://github.com/amalpvatayam67/day03-jenkins-23897

https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic

https://github.com/Fineken/Jenkins-CVE-2024-23897-Lab

https://github.com/ismailmazumder/SL7CVELabsBuilder

https://github.com/securelayer7/SL7CVELabsBuilder

https://github.com/tvasari/CVE-2024-23897

https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

https://github.com/brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo

https://github.com/slytechroot/CVE-2024-23897

https://github.com/D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins

https://github.com/safeer-accuknox/Jenkins-Args4j-CVE-2024-23897-POC

https://github.com/zgimszhd61/CVE-2024-23897-poc

https://github.com/ShieldAuth-PHP/PBL05-CVE-Analsys

https://github.com/BinaryGoodBoy0101/Jenkins-Exploit-CVE-2024-23897-Fsociety

https://github.com/i-100-user/CVE-2024-25897

https://github.com/NoSpaceAvailable/CVE-2024-23897

https://github.com/Athulya666/CVE-2024-23897

https://github.com/Pr0t0c01/CVEs

https://github.com/ifconfig-me/CVE-2024-23897

https://github.com/B4CK4TT4CK/CVE-2024-23897

https://github.com/kaanatmacaa/CVE-2024-23897

https://github.com/EvilGreys/CVE

https://github.com/wjlin0/CVE-2024-23897

https://github.com/iota4/PoC-Fix-jenkins-rce_CVE-2024-23897

https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897

https://github.com/CKevens/CVE-2024-23897

https://github.com/jenkinsci-cert/SECURITY-3314-3315

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23897

http://www.openwall.com/lists/oss-security/2024/01/24/6

http://packetstormsecurity.com/files/176840/Jenkins-2.441-LTS-2.426.3-Arbitrary-File-Read.html

Details

Source: Mitre, NVD

Published: 2024-01-24

Updated: 2025-10-24

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.99999

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest