Jenkins Improper Link Resolution Before File Access (Link Following) Vulnerability - CVE-2021-21691 - Vulnerability Database
Jenkins Improper Link Resolution Before File Access (Link Following) Vulnerability - CVE-2021-21691
Critical
Reference:
CVE-2021-21691
Title:
Jenkins Improper Link Resolution Before File Access (Link Following) Vulnerability
Overview:
Creating symbolic links is possible without the 39symlink39 agent-to-controller access control permission in Jenkins 2.318 and earlier LTS 2.303.2 and earlier.