Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21609

Опубликовано: 13 янв. 2021
Источник: redhat
CVSS3: 5.3

Описание

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsFixedRHSA-2021:063703.03.2021
Red Hat OpenShift Container Platform 4.5conmonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5jenkinsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5machine-config-daemonFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshiftFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-ansibleFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5openshift-clientsFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.5runcFixedRHSA-2021:042903.03.2021
Red Hat OpenShift Container Platform 4.6jenkinsFixedRHSA-2021:042317.02.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1925141jenkins: Missing permission check for paths with specific prefix

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.

CVSS3: 5.3
debian
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly ...

CVSS3: 5.3
github
больше 3 лет назад

Missing permission check for paths with specific prefix in Jenkins

5.3 Medium

CVSS3