#VU57987 Permissions, Privileges, and Access Controls in Jenkins and Jenkins LTS - CVE-2021-21694
Published: November 8, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions within the FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace, which leads to security restrictions bypass and privilege escalation.