Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3632 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions. |
Github GHSA |
GHSA-cv2w-q8c3-xjv7 | Agent-to-controller access control allows reading/writing most content of build directories in Jenkins |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:23:28.765Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-21697
No data.
Status : Modified
Published: 2021-11-04T17:15:08.927
Modified: 2024-11-21T05:48:51.280
Link: CVE-2021-21697
OpenCVE Enrichment
No data.
EUVD
Github GHSA