Database/Control plane, storage & DevOps
Jenkins: CLI parser expands `@file` into argument contents
CVSS 9.8CVE-2024-23897Control plane, storage & DevOpsKnown exploitedcurated
Impact
CLI parser expands @file into argument contents -> unauthenticated arbitrary file read, chains to RCE
Who can reach it
Network (remote)
What to do
Control-plane: URGENT patch; disable the CLI; rotate every credential in the Jenkins store
References
Related entries
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code executionCVE-2024-2421 · LenelS2 NetBox access control and event monitoring system (<=5.6.1)Critical
- JetBrains TeamCity: Alternative-path authentication bypassCVE-2024-27198 · JetBrains TeamCityCritical
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCVE-2024-29849 · Veeam Backup Enterprise ManagerCritical
- CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCVE-2024-32053 · CyberPower PowerPanel platform - hardcoded database, service and cloud credentialsCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.