File Path Filter Bypass in Jenkins Agent-to-Controller Security Subsystem

File Path Filter Bypass in Jenkins Agent-to-Controller Security Subsystem

CVE-2021-21686 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

Learn more about our Web Application Penetration Testing UK.