Software developers have been told to urgently patch their Jenkins servers after exploits were published for a new critical vulnerability in the product. CVE-2024-23897 could allow unauthenticated attackers with “overall/read” permission to read arbitrary files on the Jenkins controller file system.
Source: Infosecurity