Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
History

Fri, 16 Aug 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ocp Tools
CPEs cpe:/a:redhat:ocp_tools:4.12::el8
cpe:/a:redhat:ocp_tools:4.13::el8
cpe:/a:redhat:ocp_tools:4.14::el8
cpe:/a:redhat:ocp_tools:4.15::el8
Vendors & Products Redhat
Redhat ocp Tools

Fri, 16 Aug 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins jenkins
Weaknesses CWE-754
CPEs cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Vendors & Products Jenkins
Jenkins jenkins
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Aug 2024 05:15:00 +0000

Type Values Removed Values Added
Title jenkins: Arbitrary file read vulnerability through agent connections can lead to RCE
Weaknesses CWE-22
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Critical


Wed, 07 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 13:30:00 +0000

Type Values Removed Values Added
Description Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2024-08-07T13:27:11.438Z

Updated: 2024-08-07T17:29:40.580Z

Reserved: 2024-08-05T12:46:38.501Z

Link: CVE-2024-43044

cve-icon Vulnrichment

Updated: 2024-08-07T17:28:32.386Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-07T14:15:33.000

Modified: 2024-08-16T17:19:30.643

Link: CVE-2024-43044

cve-icon Redhat

Severity : Critical

Publid Date: 2024-08-07T00:00:00Z

Links: CVE-2024-43044 - Bugzilla