CVE-2021-21615

MEDIUM

Jenkins < 2.263.3 and < 2.276 - Arbitrary File Read via Workspace File Browser TOCTOU Race Condition

Title source: llm
STIX 2.1

Description

Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/01/26/2

Scores

CVSS v3 5.3
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-367
Status published
Products (3)
jenkins/jenkins < 2.263.3
jenkins/jenkins < 2.276
org.jenkins-ci.main/jenkins-core 0 - 2.263.3Maven
Published Jan 26, 2021
Tracked Since Feb 18, 2026