CVE-2024-43044: Jenkins

High severity, CVSS 8.8. EPSS: 28.8% chance of exploitation in the next 30 days.

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

Affected products

  • Jenkins Jenkins: before 2.452.4 (fixed in 2.452.4); before 2.471 (fixed in 2.471)

Published 2024-08-07. Last modified 2026-06-17.