CVE-2021-30465
Jenkins vulnerability analysis and mitigation

Overview

CVE-2021-30465 affects runc versions before 1.0.0-rc95, allowing a Container Filesystem Breakout via Directory Traversal. The vulnerability was discovered and disclosed on May 19, 2021. The issue affects runc, which is a core component of all OCI compliant container runtimes and is used in various container platforms including Docker and Kubernetes (GitHub Advisory, NVD).

Technical details

The vulnerability stems from a symlink-exchange attack that exploits a time-of-check-to-time-of-use (TOCTTOU) race condition. An attacker can trick runc into mounting outside of the container rootfs by swapping the target of a mount with a symlink. While this occurs inside a mount namespace with MS_SLAVE propagation, the attack becomes effective when combined with additional mount entries that use a subpath of the mounted-over host path as a source for subsequent mounts. The vulnerability has been assigned a CVSS v3.1 base score of 8.5 (HIGH) with vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H (GitHub Advisory, NVD).

Impact

If successfully exploited, this vulnerability allows an attacker to break out of the container and gain access to the host filesystem. In Kubernetes environments, an attacker can create a symlink in a volume to the top-level directory where volumes are sourced from, and subsequently gain access to the host system. The impact is particularly severe in multi-tenant environments where containers share volumes (GitHub Advisory, Red Hat Blog).

Exploitability

To exploit this vulnerability, an attacker must have the ability to create multiple containers with specific mount configurations and be able to run malicious code in a container that shares volumes with said configuration. The attack is facilitated when host paths used for volume management are well-known. While security mechanisms like LSMs (AppArmor/SELinux) and user namespaces can restrict the damage, they do not completely block the attack (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed in runc version 1.0.0-rc95. Users are strongly recommended to upgrade to this version or later. While there are no direct workarounds, implementing strict security profiles can help restrict potential damage. This includes using reduced capabilities, avoiding root execution in containers, enabling user namespaces, AppArmor/SELinux, and seccomp. SELinux in enforcing mode particularly helps mitigate the impact by preventing access to files or sockets not allowed by the SELinux label (Red Hat Blog, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84654MEDIUM5.4
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84656MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84655MEDIUM4.3
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84657MEDIUM4.2
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026
CVE-2026-84653LOW3.5
  • Jenkins logoJenkins
  • jenkins
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management