Description
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.
Remediation
References
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1634
http://www.openwall.com/lists/oss-security/2019/11/21/1
Related Vulnerabilities
CVE-2021-40146 Vulnerability in maven package org.apache.any23:apache-any23-core
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13
CVE-2023-27095 Vulnerability in maven package cn.hippo4j:hippo4j-core
CVE-2023-24457 Vulnerability in maven package org.jenkins-ci.plugins:keycloak
CVE-2014-0227 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core