Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
CVE ID: CVE-2024-43044
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
Vendor: Jenkins Project
Product: Jenkins
EPSS Score: 46.17% (probability of being exploited)
EPSS Percentile: 97.41% (scored less or equal to compared to others)
EPSS Date: 2025-04-12 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false