Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Remediation
References
Related Vulnerabilities
WordPress Plugin HD Webplayer Multiple SQL Injection Vulnerabilities (1.1)
WordPress Plugin Cardinity Payment Gateway for WooCommerce Cross-Site Scripting (3.0.6)
MySQL Other Vulnerability (CVE-2006-4031)
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.8)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226)