Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-103366
HistoryNov 06, 2021 - 12:00 a.m.

Jenkins Access Control Error Vulnerability (CNVD-2021-103366)

2021-11-0600:00:00
China National Vulnerability Database
www.cnvd.org.cn
14

0.003 Low

EPSS

Percentile

68.6%

Jenkins is a Jenkins open source automation server Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins has an access control error vulnerability in versions 2.318 and earlier and LTS 2.303 and earlier, which stems from the use of the FilePath API without restricting the agent’s ability to read/write access to the libs/ directory in the build directory, allowing an attacker in control of the agent process to replace the trusted library’s code with a modified variant. An attacker could exploit this vulnerability to cause the execution of unpackaged code in the Jenkins controller process.