CVE-2021-21664
An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method,…
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- jenkins/xebialabs xl deploy
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/06/10/14Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-06-10/#SECURITY-1982Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/06/10/14Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-06-10/#SECURITY-1982Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.