Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21605

Опубликовано: 13 янв. 2021
Источник: redhat
CVSS3: 8

Описание

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global config.xml file.

A flaw was found in jenkins. Users with Agent/Configure permissions can choose agent names that cause an override to the global config.xml file. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsFixedRHSA-2021:063703.03.2021
Red Hat OpenShift Container Platform 4.5conmonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5jenkinsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5machine-config-daemonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshiftFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-ansibleFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-clientsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5runcFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.6jenkinsFixedRHSA-2021:042317.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1925143jenkins: Path traversal vulnerability in agent names

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.

CVSS3: 8
debian
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with A ...

CVSS3: 8
github
больше 3 лет назад

Path traversal vulnerability in Jenkins agent names

8 High

CVSS3