Description
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
Remediation
References
Related Vulnerabilities
WordPress Plugin PostmagThemes Demo Import Arbitrary File Upload (1.0.7)
Oracle JRE CVE-2018-2790 Vulnerability (CVE-2018-2790)
Python Cryptographic Issues Vulnerability (CVE-2012-1150)
WordPress Plugin WassUp Real Time Analytics Cross-Site Scripting (1.8.3)
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1190)