Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h856-ffvv-xvr4 | Jenkins Remoting library arbitrary file read vulnerability |
Fri, 16 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ocp Tools |
|
| CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8 |
|
| Vendors & Products |
Redhat
Redhat ocp Tools |
Fri, 16 Aug 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Weaknesses | CWE-754 | |
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 08 Aug 2024 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jenkins: Arbitrary file read vulnerability through agent connections can lead to RCE | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 07 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Aug 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-03-14T19:38:08.229Z
Reserved: 2024-08-05T12:46:38.501Z
Link: CVE-2024-43044
Updated: 2024-08-07T17:28:32.386Z
Status : Modified
Published: 2024-08-07T14:15:33.000
Modified: 2025-03-14T20:15:13.470
Link: CVE-2024-43044
OpenCVE Enrichment
No data.
Github GHSA