CVE-2021-21689
FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access…
FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access…
Creating symbolic links is possible without the 'symlink' agent-to-controller access…
FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2…
When creating temporary files, agent-to-controller access to create those files…
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any…
FilePath#listFiles lists files outside directories that agents are allowed to…
File path filters in the agent-to-controller security subsystem of Jenkins…