Exploited Known exploited (KEV) Ransomware use CVE-2024-23897

Jenkins command line path traversal (CVE-2024-23897) — a flaw giving only limited read access that can lead to code execution

Jenkins Jenkins Command Line Interface (CLI) Added to KEV Aug 19, 2024 Federal remediation due 2024-09-09

A path traversal vulnerability in the command line interface of the continuous integration platform Jenkins. It is described as allowing limited read access to certain files, which can lead to code execution.

Key facts

  • CVE IDCVE-2024-23897
  • Affected (vendor / product)Jenkins Jenkins Command Line Interface (CLI)
  • CWECWE-27
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2024-09-09 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is the Jenkins command line interface, classified as path traversal involving internal directory traversal.
  • The catalog describes what it grants as limited read access to certain files.
  • It states nonetheless that this can lead to code execution, showing a read-only flaw is not necessarily minor.
  • A continuous integration platform holds privileges and credentials for the environments it delivers to, so effects reach outward.
  • Across the records this site holds as of 2026-09-04, development and CI entries with known ransomware use number 20.

1The words limited read access

The catalog describes what this vulnerability grants as limited read access to certain files. Not writing, and not arbitrary files. Yet the sentence continues that this can lead to code execution.

The scope of readingWhat can follow from it
Limited to certain filesIt can lead to code execution
No writing is possibleWhat is read becomes material for a next step
The effect looks smallIn practice it can reach execution

Even where what can be read is narrow, if it holds material for authentication or information about configuration, what becomes possible next changes. This site covers another case where configuration files and hashed passwords could be read out, and the same point recurs: a read-only flaw is not necessarily minor.

2Where a development platform sits

  1. 1Its roleChecking what was written, assembling it, and distributing it
  2. 2Privileges it holdsOften privileges to deliver into target environments
  3. 3Information it holdsCredentials and signing keys may reside there
  4. 4Direction of effectAn effect here can reach outward to where it distributes

A continuous integration platform exists to check and distribute what has been developed. By role it holds privileges over the environments it delivers to, and the credentials for them. Where it is affected, the effect can reach outward to those environments.

3The development grouping

Development and CI grouping across the records this site holds as of 2026-09-0420 unpublished entries with known ransomware useBehind boundary devices at 59 and business platforms at 32
Due date here21 daysAdded August 19, 2024, due September 9
Other products in the groupingConfiguration and issue tracking platforms also appearCounted across the records this site holds

Across the records this site holds as of 2026-09-04, 20 unpublished entries for major development and continuous integration products carry known ransomware use. Systems built for developing are targeted as much as those running the business.

4The assumption of facing inward

Development platforms are readily treated as internal systems, and may not be designed on the assumption of being reached from outside. Their privileges and the information they hold, meanwhile, are considerable. That mismatch between an inward-facing role and outward-reaching power characterises this grouping.

Why it matters

Development platforms are readily treated as internal, yet the privileges and information they hold are considerable. That mismatch between an inward-facing role and outward-reaching power is the weakness of this grouping.

FAQ

Can reading alone lead to code execution?
The catalog states so. Even a narrow scope of reading changes what becomes possible next if it holds material for authentication or configuration.
Why are development platforms targeted?
They hold privileges over the environments they deliver to and the credentials for them, so an effect can reach outward to those environments.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Development platforms#Path traversal
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.