Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Summary
| CVE | CVE-2024-23897 |
|---|---|
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-24 18:15:00 UTC |
| Updated | 2024-01-31 17:13:00 UTC |
| Description | Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. |
Risk And Classification
EPSS: 0.944660000 probability, percentile 0.999960000 (date 2026-04-21)
CISA KEV: Listed on 2024-08-19; due 2024-09-09; ransomware use Known
Problem Types: NVD-CWE-noinfo
CISA Known Exploited Vulnerability
| Vendor | Jenkins |
|---|---|
| Product | Jenkins Command Line Interface (CLI) |
| Name | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314; https://nvd.nist.gov/vuln/detail/CVE-2024-23897 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jenkins 2.441 / LTS 2.426.3 CVE-2024-23897 Scanner ≈ Packet Storm | packetstormsecurity.com | ||
| Jenkins Security Advisory 2024-01-24 | www.jenkins.io | ||
| Jenkins 2.441 / LTS 2.426.3 Arbitrary File Read ≈ Packet Storm | packetstormsecurity.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150784 Jenkins Arbitrary File Read Vulnerability (CVE-2024-23897)
- 691403 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (8b03d274-56ca-489e-821a-cf32f07643f0)
- 731109 Jenkins Core Remote Code Execution (RCE) Vulnerability (SECURITY-3314)
- 996898 Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-6f9g-cxwr-q5jr)