First published: Wed Aug 07 2024(Updated: )
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins LTS | <2.470 | |
Jenkins | <2.452.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2303466 is considered critical due to its potential for unauthorized file access.
To fix REDHAT-BUG-2303466, update Jenkins to version 2.471 or later, or to LTS 2.452.4 or later.
Affected versions in REDHAT-BUG-2303466 include Jenkins versions up to 2.470 and LTS versions up to 2.452.3.
REDHAT-BUG-2303466 poses a risk of allowing agent processes to read arbitrary files from the Jenkins controller filesystem.
There is no official workaround for REDHAT-BUG-2303466; upgrading is the recommended solution.