Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Improved user search in backend Cross-Site Request Forgery (1.2.4)
Apache Tomcat Integer Overflow or Wraparound Vulnerability (CVE-2015-8751)
Jenkins Improper Authorization Vulnerability (CVE-2021-21693)
Oracle JRE CVE-2024-21085 Vulnerability (CVE-2024-21085)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.9.5.1)