CVE-2021-21605
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.2%
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Affected products
Jenkins project · Jenkins