PT-2021-5384 · Jenkins · Jenkins

·

CVE-2021-21695

·

Published

2021-11-04

·

Updated

2024-03-06

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.318 and earlier Jenkins LTS versions 2.303.2 and earlier
Description The issue is related to the FilePath#listFiles component of the Jenkins automation server, which lacks an authorization procedure. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability allows FilePath#listFiles to list files outside directories that agents are allowed to access when following symbolic links.
Recommendations For Jenkins versions 2.318 and earlier, consider restricting access to the FilePath#listFiles component until a patch is available. For Jenkins LTS versions 2.303.2 and earlier, consider disabling the listFiles function to minimize the risk of exploitation. As a temporary workaround, avoid using the FilePath#listFiles component in sensitive areas of the Jenkins server until the issue is resolved.

Fix

Link Following

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06221
BIT-JENKINS-2021-21695
CVE-2021-21695
GHSA-CVVM-4CR9-R436
RHSA-2021:4799
RHSA-2021:4801
RHSA-2021:4827
RHSA-2021:4829
RHSA-2021:4833

Affected Products

Jenkins