PT-2021-5428 · Jenkins · Jenkins
Daniel Beck
·
Published
2021-11-04
·
Updated
2024-03-06
·
CVE-2021-21694
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.318 and earlier
Jenkins LTS versions 2.303.2 and earlier
Description
The issue is related to the absence of an authorization procedure in the Jenkins automation server. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace functions do not check any permissions in the affected Jenkins versions.Recommendations
For Jenkins versions 2.318 and earlier, consider disabling the
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace functions until a patch is available.
For Jenkins LTS versions 2.303.2 and earlier, consider disabling the FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace functions until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Missing Authorization
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins