Skip to content
COOEY

EXPOSURES › CVE-2024-23897

CVE-2024-23897

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-23897 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildsupply-chainunpatchednegligence

A path traversal flaw in Jenkins CLI allowed attackers to read files and execute code, leading to ransomware attacks.

The Jenkins Command Line Interface (CLI) suffered a path traversal vulnerability that permitted attackers to read restricted files and execute arbitrary code. This failure is critical for DIB organizations because it directly enables ransomware deployment and violates CMMC/NIST 800-171 controls around software supply chain and patch management. Organizations must verify Jenkins CLI versions and apply patches immediately to prevent similar exploits.

Shame score — A known path traversal flaw in a widely used DevOps tool was actively exploited in the wild to deploy ransomware, demonstrating severe negligence in patching and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.