Description
Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
MongoDb Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4650)
Apache version older than 1.3.27
MediaWiki CVE-2023-45372 Vulnerability (CVE-2023-45372)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6100)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Cross-Site Scripting (4.3.9)