Description
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.
Remediation
References
http://www.openwall.com/lists/oss-security/2018/02/14/1
http://www.securityfocus.com/bid/103037
https://jenkins.io/security/advisory/2018-02-14/
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2020-24164 Vulnerability in maven package com.taoensso:nippy
CVE-2020-7773 Vulnerability in npm package markdown-it-highlightjs
CVE-2022-31197 Vulnerability in maven package org.postgresql:postgresql
CVE-2022-3171 Vulnerability in maven package com.google.protobuf:protobuf-javalite
CVE-2020-17510 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-web-starter