Description
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2139
Related Vulnerabilities
CVE-2021-26272 Vulnerability in npm package ckeditor4-dev
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto
CVE-2017-1000092 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2017-1000118 Vulnerability in maven package com.typesafe.akka:akka-http-core
CVE-2018-15756 Vulnerability in maven package org.springframework:spring-web