First published: Thu Nov 04 2021(Updated: )
FilePath#untar does not check permission to create symbolic links when unarchiving a symbolic link.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2.319 | 2.319 |
redhat/jenkins LTS | <2.303.3 | 2.303.3 |
Jenkins Jenkins | <2.303.3 | |
Jenkins Jenkins | <2.319 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21687 is a vulnerability in Jenkins that allows unauthorized creation of symbolic links during untar operations.
CVE-2021-21687 has a severity rating of 9.1 (Critical).
CVE-2021-21687 allows attackers to create symbolic links without proper access checks during untar operations in Jenkins, potentially leading to unauthorized access or system compromise.
Jenkins versions 2.318 and earlier, as well as LTS 2.303.2 and earlier, are affected by CVE-2021-21687.
To fix CVE-2021-21687, upgrade to Jenkins version 2.319 or Jenkins LTS version 2.303.3.