VulnerabilityModified
CVE-2021-21643
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in…
MEDIUM 6.5EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- jenkins/config file provider
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/04/21/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2254Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/04/21/2Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2254Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.