Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
Remediation
References
Related Vulnerabilities
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3744)
WordPress Plugin WPGlobus-Multilingual Everything! Multiple Vulnerabilities (1.9.6)
WebLogic CVE-2019-2398 Vulnerability (CVE-2019-2398)
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.9.15)
WordPress Plugin Starfish Review Generation & Marketing for WordPress Security Bypass (2.0.0)