ZeroHour

CVE-2021-21602

CVSS 3.1
6.5 medium
EPSS
2%p82
Published
()
Modified
Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.

Vendors
jenkins
Products
jenkins
Weakness
CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.