DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-43044

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-43044

CGA ID

CGA-p3h6-c7gr-j772

Severity

8.8

High

CVSS V3

Description

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the ClassLoaderProxy#fetchJar method in the Remoting library.

References

  • https://images.chainguard.dev/security/CGA-p3h6-c7gr-j772

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images