First published: Thu Nov 04 2021(Updated: )
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Subversion | <=2.15.0 | |
redhat/Subversion Plugin | <2.15.1 | 2.15.1 |
maven/org.jenkins-ci.plugins:subversion | <=2.15.0 | 2.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21698 is a vulnerability in the Jenkins Subversion Plugin that allows file name restriction bypass when looking up a subversion key file on the controller from an agent.
CVE-2021-21698 has a severity rating of 7.5 (high).
Jenkins Subversion Plugin versions up to and including 2.15.0 are affected by CVE-2021-21698.
To fix CVE-2021-21698, upgrade to Jenkins Subversion Plugin version 2.15.1 or later.
You can find more information about CVE-2021-21698 at the following references: [1](http://www.openwall.com/lists/oss-security/2021/11/04/3), [2](https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2506), [3](https://access.redhat.com/errata/RHSA-2021:4833).