Related Vulnerabilities: CVE-2019-10352  

A vulnerability has been found in Jenkins before 2.186, where users with Job/Configure permission could specify a relative path escaping the base directory in the file name portion of a file parameter definition. This path would be used to store the uploaded file on the Jenkins master, resulting in an arbitrary file write vulnerability.

Severity High

Remote Yes

Type Arbitrary file overwrite

Description

A vulnerability has been found in Jenkins before 2.186, where users with Job/Configure permission could specify a relative path escaping the base directory in the file name portion of a file parameter definition. This path would be used to store the uploaded file on the Jenkins master, resulting in an arbitrary file write vulnerability.

AVG-1012 jenkins 2.185-1 2.186-1 High Fixed

https://jenkins.io/security/advisory/2019-07-17/