← Back to browse · API

CVE-2024-43044

Severity
HIGH
CVSS
8.8
EPSS
0.28782
Risk score
45.27
CISA KEV
No
PoC
No
Published
2024-08-07
Modified
2025-03-14
First seen
2026-08-07
Aliases
EUVD-2024-2593, GHSA-H856-FFVV-XVR4
Products
Jenkins Project:Jenkins patch: 2.452.4, Jenkins Project:Jenkins patch: 2.462.1, Jenkins Project:Jenkins patch: 2.471
Sources
euvd EUVD-2024-2593

Description

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

References