Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21615

Опубликовано: 26 янв. 2021
Источник: redhat
CVSS3: 5.3

Описание

Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsWill not fix
Red Hat OpenShift Container Platform 4.5conmonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5jenkinsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5machine-config-daemonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshiftFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-ansibleFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-clientsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5runcFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.6jenkinsFixedRHSA-2021:042317.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1921322jenkins: Filesystem traversal by privileged users

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.

CVSS3: 5.3
debian
около 5 лет назад

Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the ...

CVSS3: 5.3
github
больше 3 лет назад

Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins

5.3 Medium

CVSS3