Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Nov 2023, 21:23
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 |
25 Oct 2023, 18:16
Type | Values Removed | Values Added |
---|---|---|
CWE |
09 Nov 2021, 15:20
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CPE | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
|
References | (CONFIRM) https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455 - Vendor Advisory |
04 Nov 2021, 17:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-04 17:15
Updated : 2023-12-10 14:09
NVD link : CVE-2021-21690
Mitre link : CVE-2021-21690
CVE.ORG link : CVE-2021-21690
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')