Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455
Related Vulnerabilities
CVE-2013-0239 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2021-21623 Vulnerability in maven package org.jenkins-ci.plugins:matrix-auth
CVE-2014-2068 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-40634 Vulnerability in maven package org.craftercms:craftercms
CVE-2012-0803 Vulnerability in maven package org.apache.cxf:cxf-bundle