The Jenkins Credentials Plugin allowed the creation of Certificate credentials from a PKCS#12 file on the Jenkins master. Users with permission to create or update credentials could use the associated form validation to confirm the existence of files with an attacker-specified path.
Additionally, they could create credentials from any valid PKCS#12 file on the Jenkins master. With the ability to configure jobs to access these credentials, they could obtain the certificate content.
External References:
https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1322