{"id":"CVE-2021-21615","aliases":["BIT-jenkins-2021-21615","GHSA-qxp6-27gw-99cj"],"url":"https://o3.security/vulnerability/CVE-2021-21615","summary":"Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins","details":"Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.","published":"2021-01-26T18:16:18.693Z","modified":"2026-07-09T00:22:30.784169Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.main:jenkins-core","fixedVersion":"2.263.3"},{"ecosystem":"Maven","name":"org.jenkins-ci.main:jenkins-core","fixedVersion":"2.276"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/01/26/2"},{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2021-01-26/#SECURITY-2197"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:22:30.784169Z"}}