Description
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-788
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2022-31127 Vulnerability in npm package next-auth
CVE-2022-42467 Vulnerability in maven package org.apache.isis.core:isis-core-config
CVE-2023-42278 Vulnerability in maven package cn.hutool:hutool-core
CVE-2013-1921 Vulnerability in maven package org.picketbox:jbosssx
CVE-2023-28158 Vulnerability in maven package org.apache.archiva:archiva-web-common