Improper access control in Jenkins and Jenkins LTS - CVE-2024-23897

 

Improper access control in Jenkins and Jenkins LTS - CVE-2024-23897

Published: January 25, 2024 / Updated: October 30, 2024


Vulnerability identifier: #VU85786
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23897
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected application does not disable a feature of its CLI command parser that replaces an "@" character followed by a file path in an argument with the file’s contents. A remote attacker can read arbitrary files on the Jenkins controller file system, leading to arbitrary code execution.


Affected software

Jenkins
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Policy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)

How to mitigate CVE-2024-23897

Install updates from vendor's website.

Jenkins - update to 2.442
Jenkins LTS - update to 2.426.3
jenkins (Red Hat package) - addressed in versions 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516929-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.11.1706516946-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins