CVE-2024-43044 PUBLISHED

Jenkins LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

EPSS 65.90% · 98.5th percentile

Risk Scores

EPSS Score
65.90%
98.5th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0, 2.463.0
Bitnamijenkins0, 2.463.0

Timeline

References

Open in Interactive Console →