Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core(Maven) | 0 | 2.263.3 | N/A |
| org.jenkins-ci.main:jenkins-core(Maven) | 2.264 | 2.276 | N/A |
CVSS Metrics