Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Oct 1, 2024 | Jan 26, 2021 |
| Jenkins 2021 01 26 | — | Upgrade Jenkins to version 2.276Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.3 | Dec 2, 2021 | Jan 26, 2021 |
| Redhat Openshift | — | Upgrade runcUpgrade openshiftUpgrade openshift-ansibleUpgrade openshift-clientsUpgrade machine-config-daemonUpgrade conmonUpgrade jenkins | Feb 19, 2021 | Jan 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub