Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
WordPress Plugin BA Book Everything Cross-Site Scripting (1.3.24)
LimeSurvey Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2019-16175)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.11)
WebLogic CVE-2017-10178 Vulnerability (CVE-2017-10178)
WordPress Plugin Mailster-Email Newsletter for WordPress Local File Inclusion (4.0.6)