Description
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-788
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-broker
CVE-2020-26217 Vulnerability in maven package org.jvnet.hudson:xstream
CVE-2020-7650 Vulnerability in npm package snyk-broker
CVE-2023-24437 Vulnerability in maven package org.jenkins-ci.plugins:jira-steps
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-lite