AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-23899

MEDIUM · CVSS 6.5 EPSS 1.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-01-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Jenkins.

CVE
CVE-2024-23899
Severity
MEDIUM
CVSS
6.5
EPSS
1.26%
Jenkins

Original NVD Description

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)