Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
Remediation
References
Related Vulnerabilities
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10100)
WordPress Plugin WP EasyPay-Square for WordPress Cross-Site Request Forgery (3.2.0)
WordPress Plugin WP Job Manager Privilege Escalation (1.34.4)
Oracle Database Server CVE-2011-3525 Vulnerability (CVE-2011-3525)