critical
CVE-2024-23897
Jenkins CLI arbitrary file read via expandAtFiles - reads secrets, then full takeover
- Severity
- critical
- Affected product
- Jenkins
- Affected versions
- Jenkins < 2.426.3
- Affected versions
- Jenkins ≥ 2.427, < 2.442
- Fixed in
- Jenkins 2.426.3 (LTS) / 2.442
- Fixed in
- Jenkins 2.442
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Jenkins from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Jenkins from its response and reports this CVE when the detected version falls inside the affected range below.
Split per line on purpose: LTS 2.426.3 IS fixed and sorts below the 2.442 weekly boundary, so a single `lt: 2.442` row would flag a patched LTS.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →