CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
Github link:
https://github.com/slytechroot/CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
Github link:
https://github.com/slytechroot/CVE-2024-23897
GitHub
GitHub - slytechroot/CVE-2024-23897: Jenkins RCE Arbitrary File Read CVE-2024-23897
Jenkins RCE Arbitrary File Read CVE-2024-23897 . Contribute to slytechroot/CVE-2024-23897 development by creating an account on GitHub.