Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455
Related Vulnerabilities
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips-debug
CVE-2017-1000503 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-16131 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.11
CVE-2011-2732 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2020-10758 Vulnerability in maven package org.keycloak:keycloak-wildfly-server-subsystem