ID:10474 - Exploit for Improper access control in Jenkins and Jenkins LTS - CVE-2024-43044
Published: August 30, 2024
Jenkins
Jenkins LTS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the "ClassLoaderProxy#fetchJar" method in the Remoting library. A remote attacker can read arbitrary files on the Jenkins controller file system, leading to arbitrary code execution.