EXPOSURES › CVE-2024-23897
CVE-2024-23897
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA path traversal flaw in Jenkins CLI allowed attackers to read files and execute code, leading to ransomware attacks.
The Jenkins Command Line Interface (CLI) suffered a path traversal vulnerability that permitted attackers to read restricted files and execute arbitrary code. This failure is critical for DIB organizations because it directly enables ransomware deployment and violates CMMC/NIST 800-171 controls around software supply chain and patch management. Organizations must verify Jenkins CLI versions and apply patches immediately to prevent similar exploits.
Shame score — A known path traversal flaw in a widely used DevOps tool was actively exploited in the wild to deploy ransomware, demonstrating severe negligence in patching and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.