August 19, 2024 · Applied Cybernetics Group
CVE-2024-23897 — Jenkins Jenkins Command Line Interface (CLI)
known ransomware use
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
- Added to KEV
2024-08-19- Federal due date
2024-09-09- Vendor
- Jenkins
- Product
- Jenkins Command Line Interface (CLI)
- EPSS
- 100.0th percentile (score 0.945, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-23897
CISA short description
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.