ZeroHour

CVE-2021-21686

CVSS 3.1
8.1 high
EPSS
2%p79
Published
()
Modified
Description

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

Vendors
jenkins
Products
jenkins
Weakness
CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.