• News/
  • https://www.theregister.com/2024/01/30/jenkins_rce_flaw_patch/

Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released

The Register
·
Connor Jones
·
Published Jan 30, 2024
·
Updated

The number of public-facing installs of Jenkins servers vulnerable to a recently disclosed critical vulnerability is in the tens of thousands. Scans from internet security data company Shadowserver indicate roughly 45,000 instances of the hugely popular CI/CD automation server are vulnerable to CVE-2024-23897, the critical flaw disclosed on January 24. The vast majority of exposures are contained to the US and China, with 15,806 and 11,955 vulnerable servers respectively. Trailing them are India (3,572), Germany (3,487), Republic of Korea (2,204), France (1,482), and the UK (1,179). The revelation of the vast attack surface comes days after multiple exploits were made public on January 26 – themselves released just two days after the coordinated disclosure from Jenkins and Yaniv Nizry, the researcher at Sonar who first discovered the vulnerability. It means nearly a week has passed and admins are still failing to patch against a critical vulnerability that Jenkins has warned could lead to remote code execution (RCE). While there is no hard evidence to suggest active exploitation is under way, leaving a week-long window for attackers to target vulnerable servers, all while proof-of-concept exploits are publicly available, could result in successful attacks eventually. CVE-2024-23897 is the critical vulnerability disclosed by Sonar and the main reason for Jenkins attracting so much attention from the infosec community of late, although a separate high-severity flaw was also dis...

Read full article

Affected Software

1 affected component
Jenkins CI/CD automation server=2.441 and earlier
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in Jenkins CI/CD automation servers.

2

What security implications are discussed?

The article highlights that approximately 45,000 public-facing Jenkins servers remain vulnerable to remote code execution attacks despite a patch being released.

3

What software versions are affected by the vulnerability?

The vulnerability affects Jenkins CI/CD automation server versions 2.441 and earlier.

4

What action has been taken regarding the vulnerability?

A patch has been released to address the critical vulnerability in Jenkins.

5

Who reported the extent of the vulnerability in Jenkins servers?

Internet security data company Shadowserver reported on the number of vulnerable Jenkins servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released - SecAlerts