Skip to main content
Jenkins Arbitrary File Read: CVE-2024-23897 to RCE operation cover
COMING SOONIntermediate

Jenkins Arbitrary File Read: CVE-2024-23897 to RCE

The Jenkins controller at Vetrina Systems is running a version vulnerable to CVE-2024-23897 -- an args4j parser flaw that lets the CLI read any file from the server filesystem before authentication completes. An attacker used it to steal the Jenkins master key and credential store, decrypted stored service-account passwords offline, then authenticated and ran Groovy code through the Script Console to drop a persistent payload and pivot to connected build agents. Work from the SIEM access logs and XDR process evidence to trace every step from the first CLI probe to the reverse shell.

45m
7 tasks
50 points
Free

Launches in 2 days

Sep 22, 2026

Tuesday, September 22, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMXDRQuery

What you'll investigate

7 objectives unlock when this operation goes live.

1Locate the initial access vector
2Identify what was taken from the controller filesystem
3Trace the credential use
4Establish the execution method
5Identify the compromised build agent
6Pin the command-and-control destination
7Classify the initial credential exposure

Be first when it launches

Create your free account now. The moment this operation goes live on Sep 22, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free