Description
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
Remediation
References
Related Vulnerabilities
Django Resource Management Errors Vulnerability (CVE-2015-5963)
Apache HTTP Server Other Vulnerability (CVE-2021-42013)
WordPress Plugin Permalink Manager Lite Cross-Site Request Forgery (2.2.19.2)
WordPress Plugin Eu Cookie Notice Cross-Site Request Forgery (1.0.6)
WordPress Plugin iFrame Admin Pages 'url' Parameter Cross-Site Scripting (0.1)