CISA has added a critical vulnerability in Jenkins to its list of Known Exploitable Vulnerabilities (KEV). The vulnerability can be exploited for remote code execution.

Jenkins is a popular open-source automation server that helps developers automate the process of building, testing, and deploying software through continuous integration (CI) and continuous delivery (CD).
The vulnerability is tracked as CVE-2024-23897 and is the result of a weakness in the args4j command parser, which can be exploited by unauthorized attackers to read arbitrary files in the Jenkins controller file system, via the built-in command line interface (CLI).
See also: Vulnerabilities expose solar systems to hacking
“This command parser has a feature that replaces an @ character followed by a file path in an argument with the contents of the file (expandAtFiles),” the Jenkins team explained. “This feature is enabled by default and Jenkins 2.441 and earlier and LTS 2.426.2 and earlier do not disable it.”
It is worth noting that Jenkins developers have released updates security for this vulnerability on January 24. However, since then, multiple proof-of-concept (PoC) exploits have been released online .
The Shadowserver is currently monitoring more than 28,000 Jenkins instances that are vulnerable to CVE-2024-23897 (primarily in China and the United States).
According to a report by Trend Micro, the exploitation of the CVE-2024-23897 vulnerability began in March. Juniper Networks also said that the RansomEXX exploited the vulnerability to compromise the systems of Brontoo Technology Solutions, which provides technology services to Indian banks.
See also: SLUBStick Linux vulnerability allows hackers to gain complete control of the system
Following these reports, CISA added the Jenkins vulnerability to the list of Known Exploitable Vulnerabilities, warning that actors threat are actively exploiting it in attacks.
Federal Civilian Executive Branch Agencies (FCEB) have three weeks, until September 9, to secure Jenkins servers on their networks.
Although BOD 22-01 only applies to federal agencies, CISA urged all organizations to patch this vulnerability.

CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Siri vulnerability allows data theft even on locked Apple devices
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: www.bleepingcomputer.com
