Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
2021-01-26T18:16:18.693
2024-11-21T05:48:42.190
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | jenkins | < 2.263.3 | Yes |
Application | jenkins | jenkins | < 2.276 | Yes |