#VU49527 Information disclosure in Jenkins and Jenkins LTS - CVE-2021-21602
Published: January 13, 2021 / Updated: January 14, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in workspace browsers. A remote authenticated attacker can create symbolic links that allow them to access files outside workspaces using the workspace browser.