Several proof-of-concept (PoC) exploits are currently circulating for a critical Jenkins vulnerability that allows unauthorized attackers to read files . Security researchers report that some cybercriminals are actively exploiting the exploits in attacks.

Jenkins is an open-source automation server widely used in software development. It plays a critical role in automating various parts of the software and is used by organizations of all sizes, including large enterprises.
SonarSource security researchers discovered two bugs in Jenkins that could allow attackers to gain access to data on vulnerable servers and execute CLI commands under certain circumstances.
See also: Cisco: Critical vulnerability in communications software
The first critical vulnerability (CVE-2024-23897) allows unauthenticated attackers with 'overall/read' permission to read data from files on the Jenkins server. Even without this permission, it is possible to read the first few lines of the files, with the number depending on the available CLI commands.
The vulnerability relates to the default behavior of the args4j command parser in Jenkins, which automatically expands file contents into command arguments when an argument begins with the “@” character, allowing unauthorized reading of files in the Jenkins controller file system.
This vulnerability could lead to elevation of privilege and remote code execution. However, certain conditions must be met, which are different for each attack.
The second bug, tracked as CVE-2024-23898, is a cross-site hijacking issue in WebSocket, where attackers can execute CLI commands by tricking a user into clicking a malicious link. This risk could be mitigated by existing protective policies in browsers, but remains due to the lack of universal enforcement of these policies.
See also: Better Search Replace: Hackers target vulnerability in WordPress plugin
SonarSource reported the two vulnerabilities to the security on November 13, 2023. On January 24, 2024, Jenkins released fixes for the two flaws with versions 2.442 and LTS 2.426.3.

Exploits released for critical Jenkins vulnerability
As Jenkins itself released various information about the flaws, many researchers reproduced PoC exploits published on GitHub.
The PoCs are for the critical vulnerability CVE-2024-23897, which allows remote code execution on unpatched Jenkins servers. Researchers believe it has already been exploited.
The consequences of not patching the Jenkins vulnerabilities can be severe and far-reaching. First, the RCE vulnerability allows attackers to execute code , which can lead to a data breach
See also: An end to Ransomware attacks via Zero-Day vulnerabilities?
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Second, RCE attacks can cause loss or corruption of important data, as attackers can execute code that can delete or modify files.
Finally, failure to fix the RCE flaw can lead to legal and regulatory consequences, as organizations may be required to protect their data and information from such attacks.
Source: www.bleepingcomputer.com
