An arbitrary file read vulnerability in the Stapler web framework used by Jenkins allowed unauthenticated users to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master process has access to.
External Reference:
https://jenkins.io/security/advisory/2018-07-18/#SECURITY-914