CVE-2021-21687: Critical severity jenkins lts vulnerability
FilePath#untar does not check permission to create symbolic links when unarchiving a symbolic link.
Other sources
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21687?
CVE-2021-21687 is a vulnerability in Jenkins that allows unauthorized creation of symbolic links during untar operations.
What is the severity of CVE-2021-21687?
CVE-2021-21687 has a severity rating of 9.1 (Critical).
How does CVE-2021-21687 impact Jenkins?
CVE-2021-21687 allows attackers to create symbolic links without proper access checks during untar operations in Jenkins, potentially leading to unauthorized access or system compromise.
Which versions of Jenkins are affected by CVE-2021-21687?
Jenkins versions 2.318 and earlier, as well as LTS 2.303.2 and earlier, are affected by CVE-2021-21687.
How can I fix CVE-2021-21687?
To fix CVE-2021-21687, upgrade to Jenkins version 2.319 or Jenkins LTS version 2.303.3.