All latest news and releases on Hack The Box platforms.
New
Product update

New CVE Machine based on a critical vulnerability exploited in the wild.

katemous avatar
Shared by katemous • February 06, 2024

Jenkread is a Linux Machine demonstrating an arbitrary file read vulnerability (CVE-2024-23897) in the CLI component of Jenkins versions 2.441 and earlier, as well as LTS 2.426.2 and earlier.

PoCs for CVE-2024-23897 have been made public and could be leveraged by attackers to compromise unpatched Jenkins servers!

There have also been reports of the vulnerability being exploited in the wild. Get to know this vulnerability first and keep your organization secure!

Don’t have access to Dedicated Labs yet? Contact your Account Manager or hit the button below to unlock more.