Description
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
WordPress Plugin BulletProof Security Cross-Site Scripting (.52.4)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.20)
Mailman Other Vulnerability (CVE-2006-0052)
WordPress Plugin Bold Timeline Lite Cross-Site Scripting (1.1.4)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Multiple Vulnerabilities (4.0.3)