Description
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2139
Related Vulnerabilities
CVE-2009-2902 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2019-3875 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2021-3644 Vulnerability in maven package org.wildfly.core:wildfly-controller
CVE-2021-30180 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server