CVE-2021-21602

MEDIUM

Jenkins < 2.263.1, < 2.274 - Arbitrary File Read via Symlink Following

Title source: llm
STIX 2.1

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0139
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-59
Status published
Products (3)
jenkins/jenkins < 2.263.1
jenkins/jenkins < 2.274
org.jenkins-ci.main/jenkins-core 0 - 2.263.2Maven
Published Jan 13, 2021
Tracked Since Feb 18, 2026