Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-11-04 10:15
Updated : 2021-11-09 07:20
NVD link : CVE-2021-21690
Mitre link : CVE-2021-21690
JSON object : View
CWE
CWE-693
Protection Mechanism Failure
Products Affected
jenkins
- jenkins