Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-0457 Vulnerability (CVE-2015-0457)
WordPress Plugin Metronet Tag Manager Cross-Site Request Forgery (1.2.7)
MySQL CVE-2020-14870 Vulnerability (CVE-2020-14870)
WordPress Plugin Events Calendar 'ec_management.class.php' Cross-Site Scripting (6.7.11)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-32621)