090502184 - Jenkins.LTS.Command.Line.Interface.Arbitrary.File.Read
Description
This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Jenkins or LTS.
The vulnerability is due to missing validation when parsing special characters in CLI commands. A remote attacker may be able exploit this to disclose arbitrary files within the context of the application, via a crafted request.
Outbreak Alert
Cyber threat actors target Jenkins Arbitrary File Read vulnerability (CVE-2024-23897) in ransomware attacks. FortiGuard Labs continues to see active attack telemetry targeting the vulnerability.
Affected Products
Jenkins 2.441 and prior
LTS 2.426.2 and prior
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor: https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2024-08-30 | 0.00383 |
New
|