Lucene search

K
osvGoogleOSV:CVE-2021-21686
HistoryNov 04, 2021 - 5:15 p.m.

CVE-2021-21686

2021-11-0417:15:08
Google
osv.dev
10

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%