Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2000-0860)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2021-21347)
WordPress Plugin One User Avatar-User Profile Picture Unspecified Vulnerability (2.3.8)
Moodle CVE-2021-36397 Vulnerability (CVE-2021-36397)
WordPress Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2003-1599)