Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 Lyrics Karaoke Player Cross-Site Scripting (1.06)
WordPress Plugin MiwoFTP-File & Folder Manager Multiple Vulnerabilities (1.0.5)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2020-5360)
WordPress Plugin Import and export users and customers Multiple Vulnerabilities (1.14.0.2)