Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21606

Опубликовано: 13 янв. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsFixedRHSA-2021:063703.03.2021
Red Hat OpenShift Container Platform 4.5conmonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5jenkinsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5machine-config-daemonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshiftFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-ansibleFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-clientsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5runcFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.6jenkinsFixedRHSA-2021:042317.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1925159jenkins: Arbitrary file existence check in file fingerprints

EPSS

Процентиль: 46%
0.00235
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.

CVSS3: 4.3
debian
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validate ...

CVSS3: 4.3
github
больше 3 лет назад

Arbitrary file existence check in file fingerprints in Jenkins

EPSS

Процентиль: 46%
0.00235
Низкий

4.3 Medium

CVSS3