Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the ClassLoaderProxy#fetchJar method in the Remoting library.
| Software | From | Fixed in |
|---|---|---|
org.jenkins-ci.main / remoting
|
- | 3206.3208 |
org.jenkins-ci.main / remoting
|
3248 | 3248.3250 |
org.jenkins-ci.main / remoting
|
3256 | 3256.3258 |
org.jenkins-ci.main / jenkins-core
|
- | 2.452.4 |
org.jenkins-ci.main / jenkins-core
|
2.460 | 2.462.1 |
org.jenkins-ci.main / jenkins-core
|
2.470 | 2.471 |
| jenkins / jenkins | - | 2.471 |
| jenkins / jenkins | - | 2.452.4 |