#VU85786 Improper access control in Jenkins and Jenkins LTS - CVE-2024-23897
Published: January 25, 2024 / Updated: October 30, 2024
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not disable a feature of its CLI command parser that replaces an "@" character followed by a file path in an argument with the file’s contents. A remote attacker can read arbitrary files on the Jenkins controller file system, leading to arbitrary code execution.