Outbreak Alert: Jenkins RCE Attack
| Description | This article describes the detection of the Jenkins RCE Attack(CVE-2024-23897) with FortiDevSec.
CVE-2024-23897 is a critical vulnerability in Jenkins (2.441 and earlier, LTS 2.426.2 and earlier) that allows unauthenticated attackers to read arbitrary files from the Jenkins controller file system. This occurs because the CLI command parser does not disable a feature that replaces an '@' character followed by a file path in an argument with the file's contents. |
| Scope | FortiDevSec SCA scanner updated in version 24.2. |
| Solution | Detection against these vulnerabilities is empowered by the FortiDevSec Software Composition Analysis (SCA) scanner. This technology enables FortiDevSec to assess with a high level of confidence if the application codebase is vulnerable to a specific vulnerability by identifying open-source software dependencies. The SCA scanner is enabled by default. Once the scan is performed on an application, the result appears under the Software Composition Analysis tab. A step-by-step guide on how to scan an application is available in the user guide. |
