🛡️ CVE-2021-21697 — jenkins
Description
Agent-to-controller access control allows reading/writing most content of build directories in Jenkins
Agents are allowed some limited access to files on the Jenkins controller file system. The directories agents are allowed to access in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier include the directories storing build-related information, intended to allow agents to store build-related metadata during build execution. As a consequence, this allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions (build.xml and some Pipeline-related metadata).
Jenkins 2.319, LTS 2.303.3 prevents agents from accessing contents of build directories unless it’s for builds currently running on the agent attempting to access the directory.
Update [Pipeline: Nodes and Processes](https://plugins.jenkins.io/workflow-durable-task-step/) to version 2.40 or newer for Jenkins to associate Pipeline node blocks with the agent they’re running on for this fix.
If you are unable to immediately upgrade to Jenkins 2.319, LTS 2.303.3, you can install the [Remoting Security Workaround Plugin](https://www.jenkins.io/redirect/remoting-security-workaround/). It will prevent all agent-to-controller file access using FilePath APIs. Because it is more restrictive than Jenkins 2.319, LTS 2.303.3, more plugins are incompatible with it. Make sure to read the plugin documentation before installing it.
Affected software
CVE-2021-21697 is recorded against 2 packages.
- jenkins
- org.jenkins-ci.main:jenkins-core (from 2.304 up to 2.319)
Timeline and source
Published on 6 March 2024 and last revised on 3 April 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.openwall.com (Web)
www.jenkins.io (Web)
nvd.nist.gov (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| jenkins | — | — |
| org.jenkins-ci.main:jenkins-core | 2.304 | 2.319 |
References
Similar Threats
- Unknown CGA-6g73-q3c3-92w7
- Unknown CGA-7235-w595-g588
- Unknown CGA-8fh2-rcx7-55xv
- Unknown CGA-8hr7-6c5h-m383
- Unknown CGA-8mhg-rvh5-jcp3
More CVE 2021 advisories
Browse all of CVE 2021 in the advisory index.
Exploit Protection
Are you running jenkins?
CVE-2021-21697 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2021-21697 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.