CISA warns of Jenkins RCE bug exploited in ransomware attacks

Teilen:

​CISA has added a critical Jenkins vulnerability that can be exploited to gain remote code execution to its catalog of security bugs, warning that it’s actively exploited in attacks.

Jenkins is a widely used open-source automation server that helps developers automate the process of building, testing, and deploying software through continuous integration (CI) and continuous delivery (CD).

Tracked as CVE-2024-23897, this flaw is caused by a weakness in the args4j command parser that unauthenticated attackers can exploit to read arbitrary files on the Jenkins controller file system through the built-in command line interface (CLI).

“This command parser has a feature that replaces an @ character followed by a file path in an argument with the file’s contents (expandAtFiles),” the Jenkins team explained. “This feature is enabled by default and Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable it.”

Multiple proof-of-concept (PoC) exploits were published online days after Jenkins devs released security updates on January 24, with some honeypots reportedly catching exploitation attempts just one day later.

Threat monitoring service Shadowserver currently tracks over 28,000 Jenkins instances exposed to CVE-2024-23897—most of them from China (7,700) and the United States (7,368)—indicating a massive attack surface that has slowly reduced from more than 45,000 unpatched servers found in January.

According to a Trend Micro report, CVE-2024-23897 in the wild exploitation started in March, while CloudSEK claimed earlier this month that a threat actor known as IntelBroker had exploited it to breach IT service provider BORN Group.

More recently, Juniper Networks said last week the RansomEXX gang exploited the vulnerability to breach the systems of Brontoo Technology Solutions, which provides technology services to Indian banks, in late July. This ransomware attack caused widespread disruptions to retail payment systems throughout the country.

Following these reports, CISA added the security vulnerability to its Known Exploited Vulnerabilities catalog on Monday, warning that threat actors are actively exploiting it in attacks.

As mandated by the binding operational directive (BOD 22-01) issued in November 2021, Federal Civilian Executive Branch Agencies (FCEB) agencies now have three weeks until September 9 to secure Jenkins servers on their networks against ongoing CVE-2024-23897 exploitation,

Even though BOD 22-01 only applies to federal agencies, CISA strongly urged all organizations to prioritize fixing this flaw and thwart potential ransomware attacks that could target their systems.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency warned today.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:00 am, März 17, 2025
Wetter-Symbol 5°C
L: 5° | H: 6°
overcast clouds
Luftfeuchtigkeit: 80 %
Druck: 1028 mb
Wind: 9 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:09 am
Sonnenuntergang: 6:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 80 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fr. März 21 9:00 pm
Wetter-Symbol
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 0 mm 0% 7 mph 80 % 1028 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 74 % 1028 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
7° | 8°°C 0 mm 0% 10 mph 63 % 1028 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,430.62
-1.41%
Ethereum(ETH)
€1,743.68
-1.74%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.15
-2.18%
Solana(SOL)
€117.83
-5.08%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.158098
-2.34%
Shiba Inu(SHIB)
€0.000012
1.92%
Pepe(PEPE)
€0.000006
-4.55%
Peanut das Eichhörnchen(PNUT)
€0.189641
20.47%
Nach oben scrollen