CVE-2021-21698
published 2021-11-04CVE-2021-21698: Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.07%
79.3th percentile
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | make_sure_to_read_the_plugin | — | — |
| jenkins | remoting_security_workaround_plugin | — | — |
| jenkins | shared_groovy_libraries_plugin | — | — |
| jenkins | subversion | <= 2.15.0 | — |
| jenkins | subversion_plugin | — | — |
| jenkins_project | jenkins_subversion_plugin | unspecified – 2.15.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
ghsa·2022-05-24
CVE-2021-21698 [MEDIUM] CWE-22 Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
This allows attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Subversion Plugin 2.15.1 checks for the presence of and prohibits directory separator characters as part of the file name, restricting it to the intended directory.
OSV
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
osv·2022-05-24
CVE-2021-21698 [MEDIUM] Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
This allows attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Subversion Plugin 2.15.1 checks for the presence of and prohibits directory separator characters as part of the file name, restricting it to the intended directory.
Red Hat
jenkins-2-plugins/subversion: does not restrict the name of a file when looking up a subversion key
vendor_redhat·2021-11-04·CVSS 7.5
CVE-2021-21698 [HIGH] CWE-22 jenkins-2-plugins/subversion: does not restrict the name of a file when looking up a subversion key
jenkins-2-plugins/subversion: does not restrict the name of a file when looking up a subversion key
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
An incorrect access restriction vulnerability was found in the Subversion Plugin for Jenkins. An agent's ability to learn the name of a file is not restricted when looking up a subversion key file on the controller. This may allow attackers to control agent processes and read arbitrary files on the Jenkins controller file system.
Jenkins
Jenkins Security Advisory 2021-11-04
vendor_jenkins·2021-11-04·CVSS 9.1
CVE-2021-21685 [CRITICAL] Jenkins Security Advisory 2021-11-04
Title: Jenkins Security Advisory 2021-11-04
Jenkins Security Advisory 2021-11-04
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Subversion
Plugin
Descriptions
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control
SECURITY-2455
/
CVE-2021-21685, CVE-2021-216
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-04
Published