CVE-2021-21639
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node…
Does this matter?
Lower severity and a low EPSS score (2.73%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.73% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- jenkins/jenkins
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/04/07/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-07/#SECURITY-1721Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/04/07/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-07/#SECURITY-1721Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.