Description
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.
Remediation
References
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
http://rhn.redhat.com/errata/RHSA-2015-1844.html
https://bugzilla.redhat.com/show_bug.cgi?id=1205622
https://access.redhat.com/errata/RHSA-2016:0070
Related Vulnerabilities
CVE-2020-28923 Vulnerability in maven package com.typesafe.play:play
CVE-2017-1000399 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-36891 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework
CVE-2018-15685 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-2142 Vulnerability in maven package org.jenkins-ci.plugins:p4