Description
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-788
https://www.oracle.com/security-alerts/cpuapr2022.html
Related Vulnerabilities
CVE-2012-5887 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-27850 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2013-4316 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-24452 Vulnerability in maven package org.jenkins-ci.plugins:testquality-updater
CVE-2019-10329 Vulnerability in maven package org.jenkins-ci.plugins:influxdb