Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455
Related Vulnerabilities
CVE-2024-4367 Vulnerability in maven package org.webjars.bowergithub.mozilla:pdfjs-dist
CVE-2019-1003048 Vulnerability in maven package com.programmingresearch:prqa-plugin
CVE-2023-32695 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2023-29522 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2019-10249 Vulnerability in maven package org.eclipse.xtext:org.eclipse.xtext.maven.parent