Description
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-788
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2020-12480 Vulnerability in maven package com.typesafe.play:play_2.12
CVE-2020-2205 Vulnerability in maven package org.jenkins-ci.plugins:vncrecorder
CVE-2019-10440 Vulnerability in maven package org.jenkins-ci.plugins:neoload-jenkins-plugin
CVE-2015-5345 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-1000665 Vulnerability in maven package org.webjars:dojo