CVE-2021-21615
26.01.2021, 18:16
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
| Vendor | Product | Version |
|---|---|---|
| jenkins | jenkins | 𝑥 < 2.263.3 |
| jenkins | jenkins | 𝑥 < 2.276 |
𝑥
= Vulnerable software versions