CVE-2021-21686 PUBLISHED

File path filters in the agent-to-controller security subsystem of Jenkins LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

EPSS 0.28% · 51.0th percentile

Risk Scores

EPSS Score
0.28%
51.0th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

References

Open in Interactive Console →