CVE-2021-21691: jenkins: Creating symbolic links is possible without the symlink permission

Severity: Critical

CVSS Score: 9.8

Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.