#VU49528 Path traversal in Jenkins and Jenkins LTS - CVE-2021-21605
Published: January 13, 2021 / Updated: January 14, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in agent names. A remote authenticated attacker can choose agent names that cause Jenkins to override unrelated "config.xml" files.