Improper access control in Jenkins and Jenkins LTS - CVE-2024-23897
Published: January 25, 2024 / Updated: October 30, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not disable a feature of its CLI command parser that replaces an "@" character followed by a file path in an argument with the file’s contents. A remote attacker can read arbitrary files on the Jenkins controller file system, leading to arbitrary code execution.
Affected software
Jenkins LTS
OpenShift Developer Tools and Services
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Policy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2024-23897
Jenkins LTS - update to 2.426.3
jenkins (Red Hat package) - addressed in versions 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516929-3.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.11.1706516946-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8
Links to Public Exploits and PoC-codes
- Exploit #10778 - CVE-2024-23897 (CVE-2024-23897 exploit script) (October 30, 2024)
- Exploit #10748 - Jenkins 2.441 - Local File Inclusion (October 25, 2024)
- Exploit #10570 - poc-cve-2024-23897 (October 9, 2024)
- Exploit #10563 - CVE-2024-23897 (October 9, 2024)
- Exploit #10465 - CVE-2024-23897 (August 30, 2024)
- Exploit #10440 - CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability (August 30, 2024)
- Exploit #10408 - CVE-2024-23897 (August 16, 2024)
- Exploit #10260 - CVE-2024-23897-Jenkins-4.441 (July 26, 2024)
- Exploit #10134 - CVE-2024-23897 (June 28, 2024)
- Exploit #10133 - CVE-2024-23897 (June 28, 2024)
- Exploit #9816 - CVE-2024-23897 (May 13, 2024)
- Exploit #9785 - CVE-2024-23897 (May 13, 2024)
- Exploit #9669 - CVE-2024-23897 (April 5, 2024)
- Exploit #9656 - Jenkins cli Ampersand Replacement Arbitrary File Read (March 28, 2024)
- Exploit #9625 - CVE-2024-23897 (March 22, 2024)
- Exploit #9596 - CVE-2024-23897 (March 4, 2024)
- Exploit #9566 - CVE-2024-23897 (This is an exploit script for CVE-2024-23897, a vulnerability affecting certain systems. The script is intended for educational and testing purposes only. Ensure that you have the necessary permissions before using it.) (February 27, 2024)
- Exploit #9533 - CVE-2024-23897 (January 29, 2024)
External References
Related Security Bulletins
- Multiple vulnerabilities in Jenkins and Jenkins LTS
- OpenShift Developer Tools and Services for OCP 4.11 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.12 update for Jenkins and Jenkins-2-plugins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite