CVE-2024-43044 (SECURITY-3430) is an arbitrary file-read vulnerability in Jenkins Remoting affecting Jenkins 2.470 and earlier and LTS 2.452.3 and earlier. The RemoteClassLoader ClassLoaderProxy#fetchJar method, reachable through agent-to-controller Remoting operations including Channel#preloadJar, opens a requested URL without adequately validating or restricting the controller-side resource path. Consequently, a Jenkins agent can request and obtain arbitrary files from the Jenkins controller file system, bypassing intended Agent-to-Controller Access Control restrictions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a Java-based exploit for CVE-2024-43044, targeting Jenkins controllers (tested on version 2.441). The exploit leverages an arbitrary file read vulnerability that allows a Jenkins agent to fetch sensitive files from the controller. The main entry point is 'src/main/java/poc/Main.java', which provides two modes: 'mode_secret' (connects as an agent to read files) and 'mode_attach' (attaches to a running agent process for exploitation). The core logic is implemented in 'PocListener.java', which, upon successful connection, reads files such as credentials.xml, master.key, hudson.util.Secret, and secret.key from the Jenkins controller's filesystem. These files are then written locally for offline decryption, enabling the attacker to extract stored credentials. The exploit also includes utilities for forging authentication cookies and interacting with the Jenkins script console, potentially allowing command execution if a valid session is obtained. The repository is structured as a Maven project, with all Java source code under 'src/main/java/poc/'. The exploit is operational and provides a working attack chain for credential extraction from vulnerable Jenkins instances.
This repository is a Java-based exploit for CVE-2024-43044, targeting Jenkins controllers vulnerable to arbitrary file read via agent connections. The exploit is structured as a Maven project and consists of several Java classes: - `Main.java` is the entry point, supporting two main modes: `mode_secret` (using agent credentials) and `mode_attach` (attaching to a running agent process for exploitation). - `PocListener.java` orchestrates the exploitation process: it reads sensitive files from the Jenkins controller (such as master.key, secret.key, and the remember-me MAC), parses user information, and forges valid admin 'remember-me' cookies. - `CookieForger.java` and `FakeCookieForger.java` handle the cryptographic operations needed to forge cookies. - `ScriptConsole.java` uses the forged cookie to access the Jenkins script console via HTTP requests, allowing the attacker to execute arbitrary Groovy scripts (and thus system commands) on the Jenkins controller. - `RemoteFileReader.java` uses Java reflection to read files from the controller's filesystem via the agent connection. - `SystemUtils.java` and `UserParser.java` provide supporting utilities for process discovery and XML parsing. The exploit provides a full attack chain: it leverages the file read vulnerability to escalate privileges (by forging admin cookies) and achieve remote code execution. The README provides clear build and usage instructions, including Docker-based testing. The main network endpoints targeted are the Jenkins web interface (`/crumbIssuer/api/json` and `/scriptText`). The exploit is operational and demonstrates a practical attack against Jenkins instances vulnerable to CVE-2024-43044.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Jenkins arbitrary-file-read vulnerability reachable through agent connections that can lead to remote code execution.
A critical Jenkins arbitrary-file-read vulnerability reachable through agent connections that can lead to remote code execution.
An arbitrary file read vulnerability in Jenkins Remoting (Hudson) where a Jenkins agent can request and read arbitrary files from the Jenkins controller via an insufficiently restricted ClassLoaderProxy#fetchJar path/URL handling. The file read can enable follow-on compromise (e.g., credential/cookie material theft) and may facilitate escalation to remote code execution if an attacker can hijack or impersonate an agent.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.