CVE-2021-21697

CRITICAL9.1EPSS 1.5%

Agent-to-controller access control allows reading/writing most content of build directories in Jenkins

發布日:2022/5/24修改日:2025/4/3

描述

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

參考連結(6)