Jenkins Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-21692 - Vulnerability Database

Jenkins Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-21692

Critical
Reference: CVE-2021-21692
Title: Jenkins Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

FilePathrenameTo and FilePathmoveAllChildrenTo in Jenkins 2.318 and earlier LTS 2.303.2 and earlier only check 39read39 agent-to-controller access permission on the source path instead of 39delete39.