Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin Developer Tools Arbitrary File Upload (1.1.4)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17299)
WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.27)
WordPress Plugin Fast Secure Contact Form Remote Code Execution (4.0.44)