Description
File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.2)
WordPress Plugin Spiffy XSPF Player SQL Injection (0.1)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4554)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0067)