Fedora Account System
Red Hat Associate
Red Hat Customer
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
This issue has been addressed in the following products: OCP-Tools-4.15-RHEL-8 Via RHSA-2024:5405 https://access.redhat.com/errata/RHSA-2024:5405
This issue has been addressed in the following products: OCP-Tools-4.13-RHEL-8 Via RHSA-2024:5406 https://access.redhat.com/errata/RHSA-2024:5406
This issue has been addressed in the following products: OCP-Tools-4.14-RHEL-8 Via RHSA-2024:5411 https://access.redhat.com/errata/RHSA-2024:5411
This issue has been addressed in the following products: OCP-Tools-4.12-RHEL-8 Via RHSA-2024:5410 https://access.redhat.com/errata/RHSA-2024:5410