First published: Thu Nov 04 2021(Updated: )
FilePath#mkdirs does not check permission to create parent directories.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <2.303.3 | |
Jenkins Jenkins | <2.319 | |
maven/org.jenkins-ci.main:jenkins-core | >=2.304<=2.318 | 2.319 |
maven/org.jenkins-ci.main:jenkins-core | <2.303.2 | 2.303.3 |
redhat/jenkins | <2.319 | 2.319 |
redhat/jenkins LTS | <2.303.3 | 2.303.3 |
<2.303.3 | ||
<2.319 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-21685 is critical with a CVSS score of 9.1.
CVE-2021-21685 affects Jenkins versions 2.318 and earlier, as well as LTS 2.303.2 and earlier.
The vulnerability in CVE-2021-21685 is the lack of agent-to-controller access check to create parent directories in FilePath#mkdirs in Jenkins.
The remedy for CVE-2021-21685 is to update Jenkins to version 2.319 or LTS 2.303.3.
You can find more information about CVE-2021-21685 at the following references: [1] [2] [3]