CVE-2024-23897: Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-08-19. EPSS: 100% chance of exploitation in the next 30 days.
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
Affected products
- Jenkins Jenkins: before 2.426.3 (fixed in 2.426.3); before 2.442 (fixed in 2.442)
Published 2024-01-24. Last modified 2026-06-17.