Description
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2645
Related Vulnerabilities
CVE-2019-10289 Vulnerability in maven package org.jenkins-ci.plugins:netsparker-cloud-scan
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2012-2733 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-36898 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations