REDHAT-BUG-2303466: Jenkins lts vulnerability
Published Aug 7, 2024
·Updated
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the ClassLoaderProxy#fetchJar method in the Remoting library.
Affected Software
2 affected components
Jenkins Jenkins<2.470
Jenkins Jenkins LTS<2.452.3
Event History
Aug 7, 2024
Data Sourced
via Red Hat·02:20 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2303466?
The severity of REDHAT-BUG-2303466 is considered critical due to its potential for unauthorized file access.
2
How do I fix REDHAT-BUG-2303466?
To fix REDHAT-BUG-2303466, update Jenkins to version 2.471 or later, or to LTS 2.452.4 or later.
3
What are the affected versions in REDHAT-BUG-2303466?
Affected versions in REDHAT-BUG-2303466 include Jenkins versions up to 2.470 and LTS versions up to 2.452.3.
4
What impact does REDHAT-BUG-2303466 pose?
REDHAT-BUG-2303466 poses a risk of allowing agent processes to read arbitrary files from the Jenkins controller filesystem.
5
Is there a workaround for REDHAT-BUG-2303466?
There is no official workaround for REDHAT-BUG-2303466; upgrading is the recommended solution.