PT-2021-14645 · Jenkins · Jenkins

Travis Emmert

·

Published

2021-01-13

·

Updated

2024-03-06

·

CVE-2021-21602

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.274 and earlier, LTS versions 2.263.1 and earlier
Description The issue allows attackers to read arbitrary files using the file browser for workspaces and archived artifacts by following symlinks. This is possible because the file browser for workspaces, archived artifacts, and $JENKINS HOME/userContent/ follows symbolic links to locations outside the directory being browsed. Attackers with Job/Workspace permission and the ability to control workspace contents can create symbolic links to access files outside workspaces using the workspace browser.
Recommendations For Jenkins versions 2.274 and earlier, update to version 2.275 or later to resolve the issue. For LTS versions 2.263.1 and earlier, update to version 2.263.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the workspace browser and archived artifacts to minimize the risk of exploitation.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2021-21602
CVE-2021-21602
GHSA-VPJM-58CW-R8Q5
RHSA-2021:0423
RHSA-2021:0429
RHSA-2021:0637

Affected Products

Jenkins