CVE-2021-21605 PUBLISHED

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.

EPSS 0.44% · 63.0th percentile

Risk Scores

EPSS Score
0.44%
63.0th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

References

Open in Interactive Console →