#VU49529 Permissions, Privileges, and Access Controls in Jenkins and Jenkins LTS - CVE-2021-21606
Published: January 13, 2021 / Updated: January 14, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to arbitrary file existence check in file fingerprints. A remote authenticated attacker can check for the existence of XML files on the controller file system where the relative path can be constructed as 32 characters.