CVE-2021-21686

CRITICAL9.0EPSS 0.51%

Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

Published: 5/24/2022Modified: 4/3/2025

Description

File path filters in the agent-to-controller security subsystem of Jenkins LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References (6)

CVE-2021-21686 — Multiple vulnerabilities allow bypassing path filtering of agent-to-controller a · VulnScope