Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

PoC Exploit Published for Critical Jenkins Vulnerability

PoC exploit code targeting a critical Jenkins vulnerability patched last week is already publicly available.

Updating to the latest Jenkins versions has become imperative, as proof-of-concept (PoC) exploit code targeting a critical vulnerability patched last week is now publicly available.

Tracked as CVE-2024-23897 and affecting Jenkins versions before 2.442 and LTS 2.426.3, the security defect exists because the open source automation server’s command parser has a feature that replaces an ‘@’ character followed by a file path in an argument with the file’s contents.

The flaw allows unauthenticated attackers to read the first few lines of arbitrary files on the Jenkins controller file system and enables authenticated attackers to read the full contents of files.

Last week, Jenkins warned that attackers could exploit the vulnerability to read cryptographic keys stored within binary files and that, under certain conditions, these keys could be used to execute arbitrary code remotely, decrypt secrets, and perform other unauthorized actions.

Code quality platform Sonar, which identified the issue, said last week that successful exploitation of the bug could allow attackers to read build artifacts, passwords, project secrets, SSH keys, source code, and other sensitive information.

Within days after Jenkins announced patches for this and several other vulnerabilities, and after Sonar published a technical writeup on CVE-2024-23897, PoC code targeting the critical issue was published on GitHub, easing the path to malicious exploitation.

Advertisement. Scroll to continue reading.

The PoC code allows authenticated attackers to retrieve the full contents of files, while unauthenticated attackers can use it to read the first three lines of a file.

Organizations are urged to update to Jenkins versions 2.442 or LTS 2.426.3, which resolve the bug by disabling the problematic feature in the command parser. As a temporary workaround, administrators can disable access to the built-in command line interface (CLI) of Jenkins, which prevents exploitation.

Designed for building, deploying, and automating software projects, Jenkins had an estimated 44% share of the continuous integration and continuous delivery (CI/CD) market last year, making it a highly attractive target for threat actors.

Related: PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability

Related: Recent Juniper Flaws Chained in Attacks Following PoC Exploit Publication

Related: PoC Exploit Published for Recent Ubiquiti EdgeRouter Vulnerability

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.