CVE-2021-21615: Race Condition
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-21615?
CVE-2021-21615 is a vulnerability in Jenkins that allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
What is the severity of CVE-2021-21615?
CVE-2021-21615 has a severity rating of 5.3 (medium).
How can I fix CVE-2021-21615?
To fix CVE-2021-21615, upgrade Jenkins to version 2.276 or Jenkins LTS to version 2.263.3.
Where can I find more information about CVE-2021-21615?
You can find more information about CVE-2021-21615 on the CVE website, NIST NVD, and the Jenkins security advisory.
What are the CWE(s) associated with CVE-2021-21615?
The CWE(s) associated with CVE-2021-21615 are CWE-362, CWE-22, and CWE-367.