Description
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
Remediation
References
Related Vulnerabilities
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.13)
WordPress Plugin CiviCRM Multiple Vulnerabilities (5.28.0)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2017-5340)
WordPress Plugin Custom Add User Cross-Site Scripting (2.0.2)
Oracle Database Server CVE-2006-5336 Vulnerability (CVE-2006-5336)