Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
Remediation
References
Related Vulnerabilities
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.11)
WordPress Plugin WordPress File Upload Arbitrary File Upload (3.8.5)
Jenkins Improper Input Validation Vulnerability (CVE-2012-6072)
Oracle Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2001-1371)
Moodle Resource Management Errors Vulnerability (CVE-2014-7847)