Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
Remediation
References
https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-1807
Related Vulnerabilities
CVE-2020-2129 Vulnerability in maven package org.apache.maven.plugins:maven-compiler-plugin
CVE-2017-7662 Vulnerability in maven package org.apache.cxf.fediz:fediz-cxf
CVE-2022-22979 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-parent
CVE-2019-10335 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2023-24444 Vulnerability in maven package org.jenkins-ci.plugins:openid