SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21643

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in…

MEDIUM 6.5EPSS 1.08%

Does this matter?

Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.08% probability · 63th percentile
CISA KEV
Not listed
Affected
jenkins/config file provider
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.