Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.