vulnerability

Red Hat OpenShift: CVE-2021-21697: jenkins: Agent-to-controller access control allows reading/writing most content of build directories

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Nov 4, 2021
Added
Nov 30, 2021
Modified
Apr 11, 2025

Description

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.

Solution

linuxrpm-upgrade-jenkins
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.