Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Remediation
References
Related Vulnerabilities
IBM RTC CVE-2018-1694 Vulnerability (CVE-2018-1694)
Jenkins Cryptographic Issues Vulnerability (CVE-2014-2061)
WebLogic CVE-2020-2966 Vulnerability (CVE-2020-2966)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)
PleskLin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044)