Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
{
"cpes": [
"cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:maven:*:*"
],
"severity": "Medium"
}