#VU95780 Improper access control in Jenkins and Jenkins LTS - CVE-2024-43044
Published: August 12, 2024 / Updated: August 30, 2024
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the "ClassLoaderProxy#fetchJar" method in the Remoting library. A remote attacker can read arbitrary files on the Jenkins controller file system, leading to arbitrary code execution.