Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2021
Related Vulnerabilities
CVE-2019-1003045 Vulnerability in maven package de.eacg:ecs-publisher
CVE-2019-16540 Vulnerability in maven package org.jenkins-ci.plugins:support-core
CVE-2020-2163 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-11995 Vulnerability in maven package com.caucho:hessian
CVE-2011-4343 Vulnerability in maven package org.apache.myfaces.core.internal:myfaces-impl-shared