Description
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2613
Related Vulnerabilities
CVE-2018-20164 Vulnerability in npm package uap-core
CVE-2018-1000123 Vulnerability in npm package cordova-plugin-ios-keychain
CVE-2023-32081 Vulnerability in maven package io.vertx:vertx-stomp
CVE-2023-37478 Vulnerability in npm package @pnpm/macos-x64
CVE-2021-31811 Vulnerability in maven package org.apache.pdfbox:pdfbox