CVE-2024-23897
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
9.8
CVSS 3.1
100.0 %
EPSS (current)
2024-08-19
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Jenkins / Jenkins Command Line Interface (CLI)
Published: 2024-01-24 · Due (CISA): 2024-09-09
CWE: CWE-22 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | javascript/cves/2024/CVE-2024-23897.yaml | Jenkins < 2.441 - Arbitrary File Read | – |
| metasploit | auxiliary/gather/jenkins_cli_ampersand_arbitrary_file_read | auxiliary/gather/jenkins_cli_ampersand_arbitrary_file_read | 2024-01-24 |
| exploitdb | 51993 | Jenkins 2.441 - Local File Inclusion | 2024-04-15 |
References only — no downloads or instructions.