CVE-2021-21695

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
04/11/2021
Last modified:
22/11/2023

Description

FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 2.303.3 (excluding)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* 2.319 (excluding)