CVE-2024-23897

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/01/2024
Last modified:
20/12/2024

Description

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 2.426.3 (excluding)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* 2.442 (excluding)