Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jenkins | Jenkins | * | 2.375.4 (excluding) |
Jenkins | Jenkins | * | 2.394 (excluding) |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-0:2.387.3.1684911776-3.el8 | * |