CVE-2021-21692 PUBLISHED

FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.

EPSS 0.65% · 70.6th percentile

Risk Scores

EPSS Score
0.65%
70.6th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

References

Open in Interactive Console →