CVE-2021-21687 (jenkins)
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not…
FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access…
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the…
Agent processes are able to completely bypass file path filtering…
FilePath#listFiles lists files outside directories that agents are allowed to…
Creating symbolic links is possible without the 'symlink' agent-to-controller access…
FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2…
When creating temporary files, agent-to-controller access to create those files…
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any…