Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 9, 2024

CVE-2024-23897

High
EPSS 94.5%CISA KEVRansomware
Jenkins/Jenkins Command Line Interface (CLI)

Description

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

EPSS — Exploit Probability

94.5%

Higher than 100.0% of all CVEs

Required Action

https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314; https://nvd.nist.gov/vuln/detail/CVE-2024-23897

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
94.5%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Aug 19, 2024

Added to KEV

Aug 19, 2024

Remediation Due

Sep 9, 2024

Affected Product

Jenkins

Jenkins Command Line Interface (CLI)

View all Jenkins CVEs