CVE-2021-21690

CRITICAL9.0EPSS 0.50%

Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins

發布日:2022/5/24修改日:2025/4/3

描述

Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins LTS 2.303.2 and earlier.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

參考連結(6)