Description
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
Remediation
References
Related Vulnerabilities
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41305)
Squid Out-of-bounds Read Vulnerability (CVE-2023-49285)
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (4.0.3)
Oracle JRE CVE-2013-5806 Vulnerability (CVE-2013-5806)
WordPress Plugin UserPro-Community and User Profile Multiple Vulnerabilities (5.1.1)