CVE-2024-23897Disclosure(jenkins / jenkins)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for jenkins jenkins systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-09-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22CWE-27

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jenkins

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-29); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
jenkins

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-02-11: 2Mentions · 2026-03-20: 1Mentions · 2026-04-29: 3Mentions · 2026-05-20: 1Mentions · 2026-06-24: 1Mentions · 2026-08-06: 1Exploit Tool / Code · 2026-05-20: 1Active Exploitation · 2026-02-11: 2Technical Details · 2026-04-29: 2Technical Details · 2026-06-24: 1Technical Details · 2026-08-06: 102-1103-2004-2905-2006-2408-06
Signal classification4 categories
Disclosure
444.4%
Active Exploitation
222.2%
General
222.2%
Exploit
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-112
Active Exploitation2
2026-03-201
General1
2026-04-293
Disclosure2General1
2026-05-201
Exploit1
2026-06-241
Disclosure1
2026-08-061
Disclosure1
Full discourse9 posts
  • GoCocoaAI@GoCocoaAI
    Disclosure

    Sources for the three publicly verified CVEs in this brief: CVE-2024-3094 (XZ Utils / liblzma supply-chain backdoor, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-3094 CVE-2024-1709 (ConnectWise ScreenConnect auth bypass, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-1709 CVE-2024-27198 (JetBrains TeamCity auth bypass, CVSS 9.8): https://nvd.nist.gov/vuln/detail/CVE-2024-27198 Exploitation forecast data, HMM lifecycle posteriors, and aggregate panel signal via AEGIS at 23:46 UTC 2026-06-24. CVE-2024-21413 and CVE-2024-23897 NVD entries available at http://nvd.nist.gov; omitted from allowed URL set for this brief.

    Post summary

    The brief lists three disclosed CVEs with NVD links, brief technical details, and CVSS scores, without indicating exploitation or mitigation.

    0002097
    35 followersView on X
  • nksistemas@nksistemas
    Disclosure

    Alerta de Seguridad Crítica: Jenkins Expuesto a RCE por CVE-2024-23897 https://nksistemas.com/alerta-de-seguridad-critica-jenkins-expuesto-a-rce-por-cve-2024-23897/

    Post summary

    The alert announces a critical RCE flaw in Jenkins identified by CVE-2024-23897, but does not provide PoC, exploit details, or active exploitation evidence.

    00010189
    6.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-23897. CVE-2024-23897: Jenkins CLI Arbitrary File Read via args4j @ Expansion

    Post summary

    CVE-2024-23897 is identified as a Jenkins CLI arbitrary file read vulnerability via args4j expansion. The note contains no exploit details, patches, or evidence of active exploitation.

    1000023
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Jenkins CLI v< 2.442. CVE-2024-23897 is a critical arbitrary file read vulnerability in Jenkins CLI's argument parsing. CVE-2024-23897: Jenkins CLI Arbitrary File Read via args4j @ Expansion

    Post summary

    CVE-2024-23897 is a critical arbitrary file read flaw in Jenkins CLI (v<2.442) caused by improper args4j argument expansion; no PoC, patch, or exploitation evidence is provided.

    1000026
    125 followersView on X
  • Git Rated@GitRated
    Exploit

    A new AI review! gquere/pwn_jenkins ⭐3.1/5.0 pwn_jenkins is a small, pragmatic offensive-security toolkit focused on Jenkins exploitation and post-exploitation: leveraging known CVEs (notably CVE-2024-23897), dumping build logs/env vars ... https://gitrated.com/gquere/pwn_jenkins

    Post summary

    The post highlights a Jenkins exploitation toolkit (pwn_jenkins) that references CVE‑2024‑23897, suggesting exploit code availability but providing no PoC, patch, or detailed vulnerability information.

    000001
    39 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/cve-2024-23897-jenkins-cli-arbitrary-file-read-args4j-expansion #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet simply links to a research article about CVE‑2024‑23897 without providing any additional information on PoC, exploitation, patches, or vulnerability specifics.

    0000023
    125 followersView on X
  • Patrick Roland@DeusLogica
    General

    🎯 DIB Threat Briefing — March 20, 2026 1560 CVEs tracked • 25 threat actors • 14 sectors **Top DIB Targets:** • APT28 (Russia) — Defense Industrial Base + Aerospace (CVE-2024-23897, CVE-2024-1709) • APT29 (Russia) — Energy + Govt overlap (CVE-2024-3400, CVE-2024-21762) • APT40 (China) — Maritime + Tech (CVE-2024-21412, CVE-2024-21762) • Qilin — DIB + Healthcare (CVE-2024-21762, CVE-2024-3400, CVE-2024-1709) 10+ APT groups actively targeting DIB sectors. Pipeline running: dark web scan → CVE mapping → sector targeting → alerting. Data source: Roland Fleet CTI (MISP + custom graph + dark web observatory)

    Post summary

    The briefing lists CVEs linked to threat actors targeting defense industrial sectors but does not provide any technical, proof‑of‑concept, exploit, or mitigation information.

    0000068
    329 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-23897 — Stiftung Erneuerbare Freiheit Visit -- https://cti.loginsoft.com/ip/185.220.101.50 #Loginsoft #Cytellite #Cybersecurity #CVE202423897 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/wmwkMMngoP

    Post summary

    The tweet reports an active detection of exploitation against CVE-2024-23897 but provides no PoC, exploit code, patch information, or technical details.

    0000055
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-23897 — Stiftung Erneuerbare Freiheit Visit -- https://cti.loginsoft.com/ip/185.220.101.50 #Loginsoft #Cytellite #Cybersecurity #CVE202423897 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/hkVEAvx3Qk

    Post summary

    The tweet announces recent detection of activity exploiting CVE-2024-23897, indicating the vulnerability is currently being used in the wild.

    0000043
    19 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsjenkins---
Appjenkinsjenkins---

Explore more