basicsecurity.net
Proof, not just disclosure.
Outcomes / Keys to the kingdom / Story of the week
Story of the week Outcome 2 · Keys to the kingdom Selected 2026-W32 · newsworthiness 11.4 · curated from the public record

Known, weaponised, and off the list: the 208 days CVE-2024-23897 waited for CISA's KEV

A maximum-severity Jenkins flaw was public, exploited, and rated 'actively exploited' by CISA's own triage — yet it took 208 days to reach the government's authoritative Known Exploited Vulnerabilities catalog. A post-2021 measurement of a system its own maintainers say is behind.

1Front door
Unauthenticated access
2Keys to the kingdom
Identity takeover
3Lateral reach
Lateral reach
4Data at risk
Exfiltration
5Lights out
Not asserted in record
Front doorKeys to the kingdomLateral reachData at riskRansomware-confirmed
How this was drafted

The facts below are deterministic, lifted unchanged from the cited public record. The connective narrative was assembled by an audited, injection-guarded LLM over those cited facts — connective phrasing only; no invented fact, score, actor, date, or quote. Each paragraph carries a src: micro-line; where the framing is editorial, Coverage says so.audit artifact → model_id · prompt_version · input_sha256 · tsthe literal derivation trail — public-safe (no raw source text, no secrets); records only what the editor/model was given and what it emitted.

01

The story

— from one crafted request to a ransom note

On 24 January 2024 a maximum-severity flaw in Jenkins — the automation server at the centre of tens of thousands of software build-and-deploy pipelines — became public as CVE-2024-238972. What follows is not really about one vulnerability. It is a clean, post-2021 measurement of how far the authoritative exploited-vulnerability list runs behind the reality it is meant to describe.

src: publication date — CVE.org2; framing — editorial.

The mechanism is unglamorous and severe: the Jenkins command-line interface let an unauthenticated attacker read arbitrary files off the controller14 — and on a CI server those files are the crown jewels, the credentials and signing keys that reach every system it builds and ships. CISA records the severity as CVSS 9.83.

src: file-read mechanism — Jenkins advisory14; CVSS 9.8 — CISA-ADP3.

It did not stay theoretical. Public exploit code was catalogued within days6, exploitation was being reported from the field10, EPSS put the probability of exploitation at essentially one hundred percent5, and CISA later flagged it for known ransomware use4.

src: public exploit — VulnCheck6; reported exploitation — Shadowserver10; EPSS5; ransomware — CISA KEV4.

Here is the part that removes any doubt about awareness. In the machine-readable triage CISA publishes directly into the CVE record — its SSVC decision — CISA marked this flaw's exploitation status active and its automatability yes3. By CISA's own assessment, it was being actively and easily exploited.

src: SSVC exploitation=active, automatable=yes — CISA-ADP3.

And yet CISA's Known Exploited Vulnerabilities catalog — the list that sets binding federal patch deadlines, and that a great many defenders treat as the definitive record of what is being exploited — did not add CVE-2024-23897 until 19 August 20244: 208 days after it was published2. Two hundred and eight days in which it was public, weaponised, reported-exploited, and rated 'actively exploited' by CISA itself — but not yet on the list.

src: KEV date-added — CISA KEV4; publication — CVE.org2; 208-day lag is the difference.

This is not an indictment of CISA; it is a measurement of a record-keeping system under strain. NVD, the enrichment authority, has by NIST's own statements fallen behind on analysing CVEs; the CVE programme itself nearly lost funding in 2024. The KEV catalog is a floor — the exploited flaws the government has confirmed and prioritised — not the ceiling of what is being exploited. Across the known-exploited records on this site, the gap between a CVE's publication and its KEV listing runs, at the median, to the better part of a year; the live figure sits in the currency panel on the front page. CVE-2024-23897 is one face of that gap — and the reason this site cites the vendor and the CVE record directly, rather than waiting for the authoritative catalogues to catch up.

src: framing — editorial; median-gap figure is the deterministic currency measure on the landing.
02

The attack path, stage by stage

— how far they get, in the record’s own words
1

Front door — unauthenticated access narrative 1

AttackerI exploit the path traversal to read Jenkins configuration files and credentials stored on the system.
BusinessAttackers gain access to authentication tokens and system secrets, expanding their foothold.
2

Keys to the kingdom — privilege/identity takeover narrative 2

AttackerI extract sensitive files that reveal deployment scripts, build configurations, or private keys.
BusinessCompromised credentials and deployment artifacts enable lateral movement and supply chain compromise.
3

Lateral reach — past segmentation narrative 3

AttackerI leverage the read access to identify code execution pathways through Jenkins job definitions or plugin configurations.
BusinessAttackers achieve remote code execution on the Jenkins server and connected build infrastructure.
4

Data at risk — exfiltration narrative 4

AttackerI execute ransomware payloads across the Jenkins environment and connected systems.
BusinessCritical build and deployment infrastructure is encrypted, halting software delivery and operations.

The stages above are the record’s own narratives[] framing. The attacker→business framing and the ordering of stages are an editorial derivation over the record’s cited evidence, not a per-edge citation — see Coverage.

03

Who runs this path

— named, advisory-backed attribution only
Credit where the work was done — we link, we don’t republish

We did not discover this flaw, host no advisory, and redistribute no proof-of-concept code. The advisory, exploit references, and exploitation reports are the public sources' own; we link them and reason over the dates.

Scout · vendor advisory Jenkins Security Team14Scout · exploitation reporting Shadowserver Foundation10Scout · exploit cataloguing VulnCheck6

These map to our contributor profiles — /contributors/vulncheck — where every record we credit to them is aggregated.

04

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • CVSS 9.8, CISA-assigned (CISA-ADP3)
  • CISA SSVC: exploitation active (CISA-ADP3)
  • publication 2024-01-24 → KEV 2024-08-19, a 208-day gap (CVE.org2, CISA KEV4)
  • Coverage gaps — stated, not hidden

  • The connective narrative is editorial framing over the cited record; every fact is footnoted to the record's own public sources, but the argument — that the KEV catalog is a lagging floor — is ours.
  • The 208-day figure measures publication-to-KEV-listing; it is not a claim about when exploitation began, though public exploit code and field reporting both predate the listing.
  • No named individual finder is recorded in the CVE credits, so none is asserted.