Vulnerability record · CVE-2024-23897 · published 24 January 2024
CVE-2024-23897: Jenkins CLI parser arbitrary file read via @ path expansion
Jenkins · Jenkins
Jenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a file path with that file's contents. This lets an unauthenticated attacker read arbitrary files on the Jenkins controller file system, which can expose credentials and keys used to pivot further into the environment.
Description
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, confirmed exploitation in the wild, KEV listing with ransomware use, and near-maximum EPSS make this an urgent patch.
What it is
Jenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a file path with that file's contents. This lets an unauthenticated attacker read arbitrary files on the Jenkins controller file system, which can expose credentials and keys used to pivot further into the environment.
Impact
An attacker gains unauthenticated read access to arbitrary files on the Jenkins controller, including secrets and configuration that can enable lateral movement or full compromise. CISA KEV lists known ransomware campaign use, so downstream impact can extend to broader network compromise.
Attack surface
Reached over the network through the Jenkins CLI command parser; the CVSS vector shows no privileges and no user interaction required. Any network-reachable Jenkins controller with the CLI exposed is a candidate.
Exploitation
CISA KEV lists it as exploited in the wild with known ransomware campaign use, and EPSS is near 1.0 (0.99999, 99.995th percentile). Multiple references carry Exploit tags, indicating public exploit material exists.
What to do
- Upgrade Jenkins to a fixed version (2.442 or later, or LTS 2.426.3 or later) as the primary action.
- If immediate upgrade is not possible, disable CLI access over HTTP or restrict the CLI port to trusted networks per the vendor advisory.
- Remove or rotate any credentials, keys, or secrets stored on the controller that may have been exposed.
- Restrict network access to the Jenkins controller and CLI to trusted sources only.
- Monitor the vendor advisory and CISA KEV entry for updated guidance.
Detection
- Review Jenkins controller and CLI access logs for requests using '@' followed by file paths in CLI arguments.
- Alert on unexpected reads of sensitive files such as credentials.xml, secrets files, or SSH keys on the controller.
- Monitor for CLI connections from unusual or external source IPs.
- Correlate Jenkins controller activity with outbound connections or new process execution that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-23897 to the Known Exploited Vulnerabilities catalog on 19 August 2024 as "Jenkins Command Line Interface (CLI) Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-23897 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23897), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.