
Jenkins Arbitrary File Read: CVE-2024-23897 to RCE
The Jenkins controller at Vetrina Systems is running a version vulnerable to CVE-2024-23897 -- an args4j parser flaw that lets the CLI read any file from the server filesystem before authentication completes. An attacker used it to steal the Jenkins master key and credential store, decrypted stored service-account passwords offline, then authenticated and ran Groovy code through the Script Console to drop a persistent payload and pivot to connected build agents. Work from the SIEM access logs and XDR process evidence to trace every step from the first CLI probe to the reverse shell.
Launches in 2 days
Tuesday, September 22, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Sep 22, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free