Description
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
Remediation
References
Related Vulnerabilities
Jolokia Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-10899)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2014-0033)
WordPress Plugin CONTUS VBLOG-Video Blogging 'save.php' Arbitrary File Upload (1.0)
Atlassian Confluence Missing Authorization Vulnerability (CVE-2021-26085)