← Vulnerability feed

Vulnerability record · CVE-2024-23897 · published 24 January 2024

CVE-2024-23897: Jenkins CLI parser arbitrary file read via @ path expansion

Jenkins · Jenkins

Jenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a file path with that file's contents. This lets an unauthenticated attacker read arbitrary files on the Jenkins controller file system, which can expose credentials and keys used to pivot further into the environment.

9.8 CVSS 3.1 Critical CISA KEV since 19 Aug 2024 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversalCWE-27 · CWE-27
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
12References, 5 tagged exploit
17 Jun 2026Last modified by NVD

Description

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, confirmed exploitation in the wild, KEV listing with ransomware use, and near-maximum EPSS make this an urgent patch.

What it is

Jenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a file path with that file's contents. This lets an unauthenticated attacker read arbitrary files on the Jenkins controller file system, which can expose credentials and keys used to pivot further into the environment.

Impact

An attacker gains unauthenticated read access to arbitrary files on the Jenkins controller, including secrets and configuration that can enable lateral movement or full compromise. CISA KEV lists known ransomware campaign use, so downstream impact can extend to broader network compromise.

Attack surface

Reached over the network through the Jenkins CLI command parser; the CVSS vector shows no privileges and no user interaction required. Any network-reachable Jenkins controller with the CLI exposed is a candidate.

Exploitation

CISA KEV lists it as exploited in the wild with known ransomware campaign use, and EPSS is near 1.0 (0.99999, 99.995th percentile). Multiple references carry Exploit tags, indicating public exploit material exists.

What to do

  • Upgrade Jenkins to a fixed version (2.442 or later, or LTS 2.426.3 or later) as the primary action.
  • If immediate upgrade is not possible, disable CLI access over HTTP or restrict the CLI port to trusted networks per the vendor advisory.
  • Remove or rotate any credentials, keys, or secrets stored on the controller that may have been exposed.
  • Restrict network access to the Jenkins controller and CLI to trusted sources only.
  • Monitor the vendor advisory and CISA KEV entry for updated guidance.

Detection

  • Review Jenkins controller and CLI access logs for requests using '@' followed by file paths in CLI arguments.
  • Alert on unexpected reads of sensitive files such as credentials.xml, secrets files, or SSH keys on the controller.
  • Monitor for CLI connections from unusual or external source IPs.
  • Correlate Jenkins controller activity with outbound connections or new process execution that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-23897 to the Known Exploited Vulnerabilities catalog on 19 August 2024 as "Jenkins Command Line Interface (CLI) Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23897 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-5317Jenkins Fingerprints pages expose job and build namesJenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. T…KEVEPSS 23%analysed9.8CVE-2021-21690Jenkins path traversal vulnerabilityAgent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, …EPSS 2.5%9.8CVE-2021-21691Jenkins link following vulnerabilityCreating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and…EPSS 2.1%9.8CVE-2021-21692Jenkins path traversal vulnerabilityFilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access p…EPSS 2.1%9.8CVE-2021-21693Jenkins incorrect authorization vulnerabilityWhen creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-23897), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.