The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows agents) to obtain the contents of arbitrary files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2021-10-06T22:10:13

Updated: 2024-08-03T18:23:28.623Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-06T23:15:06.927

Modified: 2023-11-22T21:18:37.760

Link: CVE-2021-21683

cve-icon Redhat

No data.