{"id":55624,"date":"2024-03-19T00:00:00","date_gmt":"2024-03-19T00:00:00","guid":{"rendered":"urn:uuid:9b5a555c-3813-cdd6-eb47-f5d3b18fa58c"},"modified":"2024-03-19T00:00:00","modified_gmt":"2024-03-19T00:00:00","slug":"jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/","title":{"rendered":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"articles, news, reports,exploits &amp; vulnerabilities,research\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2024-03-19\"> <meta property=\"article:tag\" content=\"exploits &amp; vulnerabilities\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/c\/cve-2024-23897.html\"> <title>Jenkins Args4j CVE-2024-23897 Files Exposed Code at Risk | Trend Micro (US)<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\">\n<link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendmicro\/clientlibs\/trendmicro-core-2\/clientlibs\/header-footer.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/c\/cve-2024-23897.html\"><br \/>\n<meta property=\"og:title\" content=\"Jenkins Args4j CVE-2024-23897 Files Exposed Code at Risk\"><br \/>\n<meta property=\"og:description\" content=\"Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/jenkins-cover.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Jenkins Args4j CVE-2024-23897 Files Exposed Code at Risk\"><br \/>\n<meta name=\"twitter:description\" content=\"Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/jenkins-cover.png\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.189482384544\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layers *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1271354740\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"10.170731707317\">\n<div class=\"article-details\" role=\"heading\" readability=\"39.714285714286\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Exploits &amp; Vulnerabilities<\/p>\n<p class=\"article-details__description\">Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897.<\/p>\n<p class=\"article-details__author-by\">By: Arun Shaji <time class=\"article-details__date\">March 19, 2024<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<div class=\"article-details__icons\"> <!--Add This--> <\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\"> <a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\" class=\"svg-icon\" alt=\"Share\"> <\/a> <a class=\"a2a_button_print addthis_link\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\" class=\"svg-icon\" alt=\"Print\"> <\/a> <\/div>\n<p> <!--Add to Folio--> <!--Subscribe--> <\/div>\n<\/div><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"> <\/p>\n<div class=\"richText\" readability=\"37.046338672769\">\n<div readability=\"21.169336384439\">\n<p>Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-23897\" target=\"_blank\" rel=\"noopener\">CVE-2024-23897<\/a>. Jenkins employs a built-in Command-Line Interface (CLI) to facilitate interaction from script or shell environments and uses the<a href=\"https:\/\/github.com\/kohsuke\/args4j\/tree\/master\/args4j\/src\/org\/kohsuke\/args4j\" target=\"_blank\" rel=\"noopener\"> args4j library<\/a> to parse command arguments and options on the Jenkins controller during CLI command processing. The vulnerability exists in this library, allowing an unauthenticated user to read the first few lines of any files on the file system. Additionally, authenticated users can go even further by gaining the ability to read entire files.<\/p>\n<p>Given its high severity we would like to emphasize the need for swift measures to secure Jenkins installations.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Feature: expandAtFiles<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Description:<\/b> This command parser feature automatically replaces an &#8216;@&#8217; character followed by a file path in an argument with the file\u2019s content.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Enabled By Default:<\/b> Yes<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Affected Versions:<\/b> Jenkins 2.441 and earlier, LTS 2.426.2 and earlier.<br \/>&nbsp;<\/span><\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">Description: Attackers can read arbitrary files on the Jenkins controller file system using the default character encoding of the Jenkins controller process.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Permissions Impact:&nbsp;<\/span>Attackers with Overall\/Read permission can read entire files while attackers&nbsp;without Overall\/Read permissions can read the first few lines of files. The specific line count depends on available CLI commands.&nbsp;<\/li>\n<li>&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><\/li>\n<li><\/li>\n<li><span class=\"rte-red-bullet\">Over 45,000 unpatched Jenkins instances were identified by the non-profit security organization ShadowServer.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/map\/?map_type=std&amp;day=2024-01-29&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2024-23897%2B&amp;geo=all&amp;data_set=count&amp;scale=log\" target=\"_blank\" rel=\"noopener\">ShadowServer dashboard<\/a><\/span><\/li>\n<li>&nbsp;<\/li>\n<\/ul>\n<p>Figure 1 shows some of the possibilities that can result from an \u201cArbitrary File Read\u201d leading to remote code execution (RCE). More information about this can be found on the <a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-01-24\/#binary-files-note:~:text=Binary%20files%20containing,HotSpot%20based%20JVMs.\" target=\"_blank\" rel=\"noopener\">Jenkins advisory<\/a> page.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"142bf9\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig1.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig1.jpg\" alt=\"For CVE-2024-23897, shows the possibilities that can result from an \u201cArbitrary File Read\u201d leading to remote code execution \"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 1. For CVE-2024-23897, shows the possibilities that can result from an \u201cArbitrary File Read\u201d leading to remote code execution <\/figcaption><\/div>\n<\/figure><\/div>\n<div>\n<div class=\"richText\" readability=\"32.588235294118\">\n<div readability=\"12.460207612457\">\n<p>Our analysis found several attack instances originating from various regions, with the majority of the source IP addresses of the attacks originating from the Netherlands, as per <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/map\/?map_type=std&amp;day=2024-01-29&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2024-23897%2B&amp;geo=all&amp;data_set=count&amp;scale=log\">Shadowserver<\/a> data. Meanwhile, most of the targets were from South Africa, as shown in Figure 3.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig2.jpg\" alt=\"Country origin of attack attempts exploiting CVE-2024-23897 (based on Shadowserver data)\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 2. Country origin of attack attempts exploiting CVE-2024-23897 (based on Shadowserver data)<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig3.jpg\" alt=\"Distribution of targets for attack attempts exploiting CVE-2024-23897 (based on Shadowserver data)\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 3. Distribution of targets for attack attempts exploiting CVE-2024-23897 (based on Shadowserver data)<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>Most of the observed attack events lead to the use of proof-of-concept (POC) scanners. We also came across instances where RCE exploits were actively being traded \u2014 specifically, we found entries related to the sale of the CVE-2024-23897 exploit that grants unauthenticated RCE capabilities (although there is a possibility that the exploit in question may be fraudulent or fabricated).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig4.jpg\" alt=\"Sale of a CVE-2024-23897 exploit\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 4. Sale of a CVE-2024-23897 exploit<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>CVE-2024-23897 can be exploited via HTTP, WebSocket and over Secure Shell (SSH), with the first two having the highest chance of exploitation.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"9b93bd\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig5.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig5.jpg\" alt=\"HTTP exploitation flow\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 5. HTTP exploitation flow<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"37.071755725191\">\n<div readability=\"20.487022900763\">\n<p>The HTTP endpoint requires making two POST requests by default. One of the requests will send an \u201cupload\u201d request containing the commands and its arguments while the second request is a \u201cdownload\u201d request to execute the commands and receive the output.<\/p>\n<p>Upon receiving any of these requests, the following methods will be called in order:<\/p>\n<p>The <i>CliCrumbExecution<b> <\/b><\/i>method will validate the endpoint, while the <i>FullDuplexHttpService<\/i> method deals with request and response (note that <a href=\"https:\/\/github.com\/jenkinsci\/jenkins\/tree\/master\/cli\/src\/main\/java\/hudson\/cli\" target=\"_blank\" rel=\"noopener\"><i>PlainCLIProtocol<\/i><\/a> is used to make the request). Finally, the <i>CmdLineParser <\/i>method, which uses the vulnerable args4j library, is used to parse arguments from the CLI Input.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"db4009\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig6.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig6.jpg\" alt=\"Method calls\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 6. Method calls<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<h2><span class=\"body-subhead-title\">The Jenkins PlainCLIProtocol<\/span><\/h2>\n<p>The Jenkins <i>PlainCLIprotcol<\/i> java class uses a specific binary format that consists of various opcodes and sequential frames. <b><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"eccffc\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig7.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig7.jpg\" alt=\"Opcode mapping; these values represent the ordinal positions of each opcode in the Op enum.\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 7. Opcode mapping; these values represent the ordinal positions of each opcode in the Op enum.<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32.571428571429\">\n<div readability=\"11.667377398721\">\n<p>Each opcode has a Boolean property <i>clientSide<\/i> indicating whether it is sent from the client to the server (true) or from the server to the client (false). These opcodes are used to define the different types of operations that can be exchanged between the client and server in the CLI protocol.<\/p>\n<h2><span class=\"body-subhead-title\">The Jenkins binary format<\/span><\/h2>\n<p>Jenkins has a specific binary format that is based off sequential frames. Figure 8 depicts the Jenkins binary format (as provided by <a href=\"https:\/\/www.linkedin.com\/in\/alexanderwilliamscyber\" target=\"_blank\" rel=\"noopener\">Alex Williams<\/a>):<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig8.jpg\" alt=\"Jenkins binary format\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 8. Jenkins binary format<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"37.142289348172\">\n<div readability=\"19.809220985692\">\n<p>The binary format for this protocol involves framing each message with an int length followed by a byte opcode, and then finally by the actual data.<\/p>\n<p>The following is a breakdown of the binary format for a generic message:<\/p>\n<p><b>Length Field (4 bytes): <\/b>This represents the length of the message excluding the length field itself and the opcode. It is Encoded as a 32-bit signed integer in network byte order (big-endian).<\/p>\n<p><b>Opcode Field (1 byte): <\/b>This represents the operation code (opcode) for the message.<b><\/b><\/p>\n<p><b>Data Field: <\/b>This is the actual data specific to the opcode.<\/p>\n<h2><span class=\"body-subhead-title\">Vulnerable Code<\/span><\/h2>\n<p>The vulnerable code can be found in the <a href=\"https:\/\/github.com\/kohsuke\/args4j\/tree\/master\/args4j\/src\/org\/kohsuke\/args4j\" target=\"_blank\" rel=\"noopener\">Args4j<\/a> library<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"b09cfe\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig9.jpg\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig9.jpg\" alt=\"Replacing an \u201c@\u201d character followed by a file path in an argument with the file\u2019s content\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 9. Replacing an \u201c@\u201d character followed by a file path in an argument with the file\u2019s content<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<h2><span class=\"body-subhead-title\">Functionality in regular use<\/span><\/h2>\n<p>Normally, the \u201c@\u201d in Jenkins-cli is used to specify a file containing the bearer token or <i>username:password<\/i> from a file.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig10.jpg\" alt=\"Normal usage of Jenkins-cli \u201c@\u201d\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 10. Normal usage of Jenkins-cli \u201c@\u201d<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>Using an authenticated command with Jenkins-cli will produce the following output:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig11.jpg\" alt=\"Error output of a normal authenticated command\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 11. Error output of a normal authenticated command<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>Using the feature \u201c@\u201d to specify the <i>password.txt<\/i> file in <i>-auth <\/i>switch produces the following:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig12.jpg\" alt=\"An authenticated output from jenkins using the \u201c-auth\u201d switch. Note that Jenkins recommends the use of a file to load the authentication credentials.\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 12. An authenticated output from jenkins using the \u201c-auth\u201d switch. Note that Jenkins recommends the use of a file to load the authentication credentials.<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<h2><span class=\"body-subhead-title\">Vulnerability scenario<\/span><\/h2>\n<p>Passing \u201c@\u201d as an argument to available Jenkins-cli commands will result in the output shown in Figure 13.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig13.jpg\" alt=\"Exploiting the flaw\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 13. Exploiting the flaw<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>As seen in the image, data is exposed in the error output, even though the \u201cversion\u201d command does not take any arguments.<\/p>\n<p>The extent of information disclosure is contingent on the command argument patterns. For instance, if the argument allows list inputs, it signifies a potential for more extensive data exposure:<\/p>\n<p>$ java -jar jenkins-cli.jar -s http:\/\/172.17.0[.]1:8080\/ -auth admin:pass reload-job @\/etc\/passwd<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig14.jpg\" alt=\"Reading the entire file\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 14. Reading the entire file<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"39.832083958021\">\n<div class=\"responsive-table-wrap\" readability=\"25.571214392804\">\n<p>In our recent research, we&#8217;ve identified <a href=\"https:\/\/github.com\/jenkinsci\/jenkins\/blob\/master\/core\/src\/main\/java\/hudson\/cli\/ReloadJobCommand.java\" target=\"_blank\" rel=\"noopener\"><i>reload-job<\/i><\/a> as an alternative to the commonly used <a href=\"https:\/\/github.com\/jenkinsci\/jenkins\/blob\/master\/core\/src\/main\/java\/hudson\/cli\/CreateNodeCommand.java\" target=\"_blank\" rel=\"noopener\"><i>connect-node<\/i><\/a> command for reading multiple lines.<\/p>\n<p>Other examples include <i>delete-job, delete-node, disconnect-node, offline-node, <\/i>and<i> online-node<\/i>.<\/p>\n<p><span class=\"body-subhead-title\">Alternative attack vector: unauthenticated users<\/span><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\">\n<tbody readability=\"2\">\n<tr>\n<th scope=\"col\">Command<\/th>\n<th scope=\"col\">Details<\/th>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">help<\/td>\n<td width=\"197\">Adds jobs to view<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"24\" width=\"197\">who-am-i<\/td>\n<td width=\"197\">Reports credential and permissions<\/td>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">restart<\/td>\n<td width=\"197\">Restarts Jenkins<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"24\" width=\"197\">shutdown<\/td>\n<td width=\"197\">Immediately shuts down Jenkins server<\/td>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">enable-job<\/td>\n<td width=\"197\">Enables a job<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><sup>Table 1. Alternative attack vector for unauthenticated users<\/sup><\/p>\n<h2><span class=\"body-subhead-title\">Alternative Attack Vectors: Authenticated users<\/span><\/h2>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\" height=\"10%\">\n<tbody readability=\"8.5\">\n<tr>\n<th scope=\"col\">Command<\/th>\n<th scope=\"col\">Details<\/th>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">add-job-to-view<\/td>\n<td width=\"197\">Adds jobs to view.<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td height=\"24\" width=\"197\">build<\/td>\n<td width=\"197\">Builds a job, and optionally waits until its completion<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"24\" width=\"197\">cancel-quiet-down<\/td>\n<td width=\"197\">Cancels the effect of the quiet-down command.<\/td>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">clear-queue<\/td>\n<td width=\"197\">Clears the build queue<\/td>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">connect-node<\/td>\n<td width=\"197\">Reconnects to a node(s)<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"24\" width=\"197\">console<\/td>\n<td width=\"197\">Retrieves console output of a build.<\/td>\n<\/tr>\n<tr>\n<td height=\"24\" width=\"197\">copy-job<\/td>\n<td width=\"197\">Copies a job.<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">create-credentials-by-xml<\/td>\n<td width=\"197\">Creates credential via XML<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">create-credentials-domain-by-xml<\/td>\n<td width=\"197\">Create credentials domain via XML<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td height=\"24\" width=\"197\">create-job<\/td>\n<td width=\"197\">Creates a new job by reading stdin as a configuration XML file<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><sup>Table 2. Alternative attack vector for authenticated users<\/sup><\/p>\n<h2><span class=\"body-subhead-title\">Attack request via Windows<\/span><\/h2>\n<p>In the context of this attack, where a request originates from a Windows machine to a Jenkins Linux server, the observed encoding is identified as windows-1252.<\/p>\n<p><b>&nbsp;<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig15.jpg\" alt=\"Windows Attack request (windows-1252)\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 15. Windows Attack request (windows-1252)<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<h2><span class=\"body-subhead-title\">Attack Request via Linux<\/span><\/h2>\n<p>If the request is from a Linux machine to a Jenkins Linux server, the observed encoding is UTF-8 in the context of this attack.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig16.jpg\" alt=\"Linux Attack request (UTF-8)\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 16. Linux Attack request (UTF-8)<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<h2><span class=\"body-subhead-title\">Attack Request via WebSocket<\/span><\/h2>\n<p>WebSocket-based attack requests will have masking on the data, resulting in user input being invisible.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/c\/jenkins-args4j-cve-2024-23897-files-exposed,-code-at-risk-\/Fig17.jpg\" alt=\"WebSocket attack request\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 17. WebSocket attack request<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"37.5\">\n<div readability=\"20\">\n<p>Jenkins patched CVE-2024-23897 in versions 2.442 and LTS 2.426.3 by disabling the problematic command parser feature. Users are strongly recommended to apply this update at the soonest possible time to avoid any potential security incidents.<\/p>\n<p>The following protections exist to detect and protect Trend customers against CVE-2024-23897:<\/p>\n<p><b>Trend Vision One Endpoint Security, Trend Cloud One &#8211; Workload and Endpoint Security, Deep Security and Vulnerability Protection IPS Rules<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">1011966 &#8211; Jenkins Arbitrary File Read Vulnerability Over HTTP (CVE-2024-23897)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">1011976 &#8211; Jenkins Arbitrary File Read Vulnerability Over WebSocket (CVE-2024-23897)<\/span><\/li>\n<\/ul>\n<p><b>Trend Micro Cloud One &#8211; Network Security &amp; TippingPoint Filters<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">43766: HTTP: Jenkins CI Server Arbitrary File Read Vulnerability<\/span><\/li>\n<\/ul>\n<p><b>Trend Vision One Network Sensor and Trend Micro Deep Discovery Inspector (DDI) Rule<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">4997 &#8211; CVE-2024-23897 &#8211; Jenkins Authentication Bypass Exploit &#8211; HTTP (Request)<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/c\/cve-2024-23897.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9555,9509],"class_list":["post-55624","post","type-post","status-publish","format-standard","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-19T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk\",\"datePublished\":\"2024-03-19T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/\"},\"wordCount\":1391,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/jenkins-cover:Large?qlt=80\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/\",\"name\":\"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/jenkins-cover:Large?qlt=80\",\"datePublished\":\"2024-03-19T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/jenkins-cover:Large?qlt=80\",\"contentUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/jenkins-cover:Large?qlt=80\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/","og_locale":"en_US","og_type":"article","og_title":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-03-19T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk","datePublished":"2024-03-19T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/"},"wordCount":1391,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/","url":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/","name":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80","datePublished":"2024-03-19T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#primaryimage","url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80","contentUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/jenkins-cover:Large?qlt=80"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/jenkins-args4j-cve-2024-23897-files-exposed-code-at-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55624"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55624\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}