CVE-2021-21605: Input Validation
A flaw was found in jenkins. Users with Agent/Configure permissions can choose agent names that cause an override to the global config.xml file. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global config.xml file.
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override unrelated config.xml files. If the global config.xml file is replaced, Jenkins will start up with unsafe legacy defaults after a restart.
Jenkins 2.275, LTS 2.263.2 ensures that agent names are considered valid names for items to prevent this problem.
In case of problems, this change can be reverted by setting the Java system property jenkins.model.Nodes.enforceNameRestrictions to false.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612433584-1.el7 - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2:2.0.21-1.rhaos4.5.el7 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612434332-1.el7 - Upgrade
Upgrade
redhat/machine-config-daemonto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102050524.p0.git.0.9229406.el7 - Upgrade
Upgrade
redhat/openshift-ansibleto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102031005.p0.git.0.c6839a2.el7 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102051529.p0.git.3612.61b096a.el8 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 0:1.0.0-72.rhaos4.5.giteadfc6b.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612434510-1.el8 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.263.2 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
redhat/jenkins LTSto a version that resolves this vulnerability.Fixed in 2.263.2 - Upgrade
Upgrade
Jenkinsto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
Jenkins (LTS)to a version that resolves this vulnerability.Fixed in 2.263.2 - Configuration
If problems occur after replacing the global config.xml file, revert the change by setting the Java system property jenkins.model.Nodes.enforceNameRestrictions to false.
Jenkins jenkins.model.Nodes.enforceNameRestrictions = false - Compensating control
Limit users with Agent/Configure permissions so they cannot choose agent names that override the global config.xml file (data confidentiality/integrity and availability impact).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-21605?
CVE-2021-21605 has a high severity level, impacting data confidentiality, integrity, and system availability.
How do I fix CVE-2021-21605?
To remediate CVE-2021-21605, upgrade to Jenkins version 2.275 or LTS version 2.263.2.
Who is affected by CVE-2021-21605?
CVE-2021-21605 affects Jenkins versions 2.274 and earlier, as well as all LTS versions prior to 2.263.2.
What impacts can CVE-2021-21605 have on my system?
CVE-2021-21605 can lead to unauthorized access and manipulation of the global config.xml file, compromising data security.
How can I identify if my Jenkins installation is vulnerable to CVE-2021-21605?
You can determine if your Jenkins installation is vulnerable by checking its version against the affected versions listed in CVE-2021-21605.