Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.263.3"
},
{
"introduced": "0"
},
{
"fixed": "2.276"
}
]
}