Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2020-2545 Vulnerability (CVE-2020-2545)
WordPress Plugin Hunk External Links Cross-Site Scripting (3.0.5)
WordPress Plugin IGIT Posts Slider Widget TimThumb Arbitrary File Upload (1.1)
Apache Tomcat Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-12617)