Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Image and Video Gallery with Thumbnails SQL Injection (2.0.3)
WordPress Plugin Mingle Forum 'edit_post_id' Parameter SQL Injection (1.0.31)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0276)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1692)