Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the ClassLoaderProxy#fetchJar
method in the Remoting library.
{ "cpes": [ "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:maven:*:*" ], "severity": "High" }