CVE-2021-21690
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
9.0
CRITICAL
CVSS 3.1
EPSS 2.5%
Description
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins LTS 2.303.2 and earlier.
How to fix CVE-2021-21690
To remediate CVE-2021-21690, upgrade the affected package to a fixed version below.
- Bitnami/jenkins—upgrade to 2.319.0 or later
- —upgrade to 2.303.3 or later
Is CVE-2021-21690 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.319.0
- from 0, < 2.303.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.0 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |