Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
Remediation
References
Related Vulnerabilities
Magento Deserialization of Untrusted Data Vulnerability (CVE-2019-8141)
TYPO3 Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-26229)
Oracle JRE CVE-2013-0427 Vulnerability (CVE-2013-0427)
Django Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-31542)