Security Advisory

CVE-2024-43044

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-08-07 13:27:11
Last updated 2025-03-14 19:38:08
Assigner jenkins
State PUBLISHED

Description

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.