Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
Remediation
References
Related Vulnerabilities
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21670)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Multiple Vulnerabilities (4.0.3)
jQuery Validation Uncontrolled Resource Consumption Vulnerability (CVE-2021-21252)
WordPress Plugin TinyMCE Advanced Cross-Site Request Forgery (4.1)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2196)