CVE-2024-23897
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
- CVSS v4.0
- 9.3 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-08-19, used in ransomware campaigns
- Nuclei
- high
- Published
- 2024-01-24
- Updated
- 2025-10-21
Proof-of-concept exploits (61)
- http://packetstormsecurity.com/files/176840/Jenkins-2.441-LTS-2.426.3-Arbitrary-File-Read…
- https://www.vicarius.io/vsociety/posts/the-anatomy-of-a-jenkins-vulnerability-cve-2024-23…
- 10T4/PoC-Fix-jenkins-rce_CVE-2024-238974★ · 2024-01-27
- 3yujw7njai/CVE-2024-2389715★ · 2024-01-27
- AbraXa5/Jenkins-CVE-2024-238971★ · 2024-02-04
- AiK1d/CVE-2024-2389715★ · 2024-01-27
- Athulya666/CVE-2024-238971★ · 2024-05-03
- B4CK4TT4CK/CVE-2024-238970★ · 2024-02-13
- CKevens/CVE-2024-2389715★ · 2024-01-27
- D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins4★ · 2024-12-08
- JAthulya/CVE-2024-238971★ · 2024-05-03
- Maalfer/CVE-2024-2389713★ · 2025-04-30
- Nebian/CVE-2024-238971★ · 2024-02-21
- P4x1s/CVE-2024-2389715★ · 2024-01-27
- Praison001/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability3★ · 2024-02-09
- R0XDEADBEEF/CVE-2024-238970★ · 2024-01-28
- Shinkirou789/Jenkins-2.441-exploit0★ · 2025-02-12
- Surko888/Surko-Exploit-Jenkins-CVE-2024-238970★ · 2024-06-01
- ThatNotEasy/CVE-2024-238972★ · 2024-03-02
- Vozec/CVE-2024-2389717★ · 2024-04-16
- WLXQqwer/Jenkins-CVE-2024-23897-0★ · 2024-02-04
- binganao/CVE-2024-2389799★ · 2024-02-01
- brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo0★ · 2025-04-07
- cc3305/CVE-2024-238970★ · 2024-10-28
- godylockz/CVE-2024-2389743★ · 2025-11-20
- h4x0r-dz/CVE-2024-23897207★ · 2024-01-28
- ifconfig-me/CVE-2024-238970★ · 2024-02-17
- iota4/PoC-Fix-jenkins-rce_CVE-2024-238974★ · 2024-01-27
- iota4/PoC-jenkins-rce_CVE-2024-238974★ · 2024-01-27
- jopraveen/CVE-2024-238971★ · 2024-01-29
- kaanatmacaa/CVE-2024-2389722★ · 2024-02-05
- murataydemir/CVE-2024-238970★ · 2024-05-07
- nbalazs1337/poc-jenkins0★ · 2024-02-06
- pulentoski/CVE-2024-23897-Arbitrary-file-read0★ · 2024-11-18
- quentin33980/ToolBox-qgt0★ · 2024-05-10
- r0xDB/CVE-2024-238970★ · 2024-01-28
- raheel0x01/CVE-2024-238970★ · 2024-01-28
- slytechroot/CVE-2024-238970★ · 2025-03-23
- tamatee/test_cve_2024_238970★ · 2024-11-07
- tvasari/CVE-2024-238970★ · 2025-04-04
- verylazytech/CVE-2024-2389710★ · 2024-11-26
- viszsec/CVE-2024-238975★ · 2024-01-31
- vmtyan/poc-cve-2024-238972★ · 2024-01-26
- wjlin0/CVE-2024-2389786★ · 2024-03-16
- xaitax/CVE-2024-2389780★ · 2024-02-29
- yoryio/CVE-2024-238975★ · 2024-03-13
- MachiavelliII/CVE-2024-238970★ · 2026-08-28
- Ap0dexMe0/CVE-2024-23897
- Dungsocool/CVE-2024-23897
- GraySignal/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability
- aadi0258/Exploit-CVE-2024-23897
- classic130/CVE-2024-23897-Jenkins-4.441
- razureink/cve-2024-23897-jenkins_lfi_reproduction
- rivaedoardo62-boop/cve-2024-23897-jenkins-poc
- vmc8ll/poc-CVE-2024-23897
- Anekant-Singhai/Exploits
- Cheepsss/SPS_POC
- chengbochuan3/CVE-CICD-Security
- chengbochuan3/CVE-Learn
- cleverg0d/CVEs
- kwekre/poc