diff --git a/jenkins-docker/server/CVE-2024-23897-disable-cli.groovy b/jenkins-docker/server/CVE-2024-23897-disable-cli.groovy
new file mode 100644
index 0000000..ba967cf
--- /dev/null
+++ b/jenkins-docker/server/CVE-2024-23897-disable-cli.groovy
@@ -0,0 +1,49 @@
+/*
+The MIT License
+
+Copyright (c) 2024, CloudBees, Inc.
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in
+all copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+THE SOFTWARE.
+*/
+
+// Disable CLI access over HTTP
+def removal = { lst ->
+  try {
+    lst.each { x ->
+      if (x.getClass().name?.contains("CLIAction")) {
+        println("Removing extension ${x.getClass().getName()} CVE-2024-23897")
+        lst.remove(x)
+      }
+    }
+  } catch(Exception e) {
+    e.printStackTrace()
+  }
+}
+def j = jenkins.model.Jenkins.get();
+removal(j.getExtensionList(hudson.cli.CLIAction.class))
+removal(j.getExtensionList(hudson.ExtensionPoint.class))
+removal(j.getExtensionList(hudson.model.Action.class))
+removal(j.getExtensionList(hudson.model.ModelObject.class))
+removal(j.getExtensionList(hudson.model.RootAction.class))
+removal(j.getExtensionList(hudson.model.UnprotectedRootAction.class))
+removal(j.getExtensionList(java.lang.Object.class))
+removal(j.getExtensionList(org.kohsuke.stapler.StaplerProxy.class))
+removal(j.actions)
+
+println "Done!"
diff --git a/jenkins-docker/server/Dockerfile b/jenkins-docker/server/Dockerfile
index ffd9f02..45af170 100644
--- a/jenkins-docker/server/Dockerfile
+++ b/jenkins-docker/server/Dockerfile
@@ -54,6 +54,10 @@
 
 COPY number-executors.groovy $JENKINS_REF/init.groovy.d/
 COPY setCredentials.groovy $JENKINS_REF/init.groovy.d/
+
+# TODO: CVE-2024-23897 Groovy workaround can be removed only after upgrading to 2.442, LTS 2.426.3
+COPY CVE-2024-23897-disable-cli.groovy $JENKINS_REF/init.groovy.d/
+
 COPY gerrit-ci-scripts.xml $JENKINS_REF/jobs/gerrit-ci-scripts/config.xml
 COPY gerrit-ci-scripts-manual.xml $JENKINS_REF/jobs/gerrit-ci-scripts-manual/config.xml
 COPY org.jenkinsci.plugins.workflow.libs.GlobalLibraries.xml $JENKINS_REF/
