<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:20:09.101229+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-06108</id>
    <title>bdu:2021-06108</title>
    <updated>2026-10-03T18:20:09.227871+00:00</updated>
    <content>bdu:2021-06108</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-06108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-jenkins-2021-21686</id>
    <title>BIT-jenkins-2021-21686</title>
    <updated>2026-10-03T18:20:09.227929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: jenkins</p>
<p>File path filters in the agent-to-controller security subsystem of Jenkins LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-jenkins-2021-21686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-22403</id>
    <title>EUVD-2026-22403</title>
    <updated>2026-10-03T18:20:09.227965+00:00</updated>
    <content>EUVD-2026-22403</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-22403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21686</id>
    <title>fkie_cve-2021-21686</title>
    <updated>2026-10-03T18:20:09.227978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-21686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4g38-hrm4-rg94</id>
    <title>GHSA-4g38-hrm4-rg94 — Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins</title>
    <updated>2026-10-03T18:20:09.228000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.main:jenkins-core</p>
<p>The agent-to-controller security subsystem limits which files on the Jenkins controller can be accessed by agent processes.</p>
<p>Multiple vulnerabilities in the file path filtering implementation of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allow agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems.</p>
<p>SECURITY-2444 / CVE-2021-21686: File path filters do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.</p>
<p>We expect that most of these vulnerabilities have been present since [SECURITY-144 was addressed in the 2014-10-30 security advisory](https://www.jenkins.io/security/advisory/2014-10-30/).</p>
<p>Jenkins 2.319, LTS 2.303.3 addresses these security vulnerabilities.</p>
<p>SECURITY-2444 / CVE-2021-21686: File path filters canonicalize paths, preventing operations from following symbolic links to outside allowed directories.</p>
<p>As some common operations are now newly subject to access control, it is expected that plugins sending commands from agents to the controller may start failing. Additionally, the newly introduced path canonicalization means that instances using a custom builds directory ([Java system property jenkins.model.Jenkins.buildsDir](https://www.jenkins.io/doc/book/managing/system-properties/#jenkins-model-jenkins-buildsdir)) or partitioning `JENKINS_HOME` using symbolic links may fail access control checks. See [the docume…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4g38-hrm4-rg94"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-21686</id>
    <title>gsd-2021-21686</title>
    <updated>2026-10-03T18:20:09.228044+00:00</updated>
    <content>gsd-2021-21686</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-21686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4799</id>
    <title>RHSA-2021:4799 — Red Hat Security Advisory: OpenShift Container Platform 4.6.51 packages and security update</title>
    <updated>2026-10-03T18:20:09.228057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jenkins: FilePath#mkdirs does not check permission to create parent directories jenkins: File path filters do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories jenkins: FilePath#untar does not check permission to create symbolic links when unarchiving a symbolic link jenkins: FilePath#reading(FileVisitor) does not reject any operations allowing users to have unrestricted read access jenkins: FilePath#unzip and FilePath#untar were not subject to any access control jenkins: Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path jenkins: Creating symbolic links is possible without the symlink permission jenkins: The operations FilePath#renameTo and FilePath#moveAllChildrenTo only check read permission on the source path jenkins: When creating temporary files, permission to create files is only checked after they’ve been created. jenkins: FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions jenkins: FilePath#listFiles lists files outside directories with agent read access when following symbolic links. jenkins: Agent-to-controller access control allowed writing to sensitive directory used by Pipeline: Shared Groovy Libraries Plugin jenkins: Agent-to-controller access control allows reading/writing most content of build directories jenkins-2-plugins/subversion: does not restrict the na…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4799"/>
  </entry>
</feed>
