Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21623

Опубликовано: 18 мар. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

A flaw was found in Jenkins Matrix Authorization Strategy Plugin. The jenkins plugin does not correctly perform permission checks, as consequences this allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected
Red Hat OpenShift Container Platform 4.8jenkinsFixedRHSA-2021:243727.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-273
https://bugzilla.redhat.com/show_bug.cgi?id=1940489jenkins-2-plugins/matrix-auth: Incorrect permission checks in Matrix Authorization Strategy Plugin

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

CVSS3: 6.5
github
больше 3 лет назад

Incorrect permission checks in Jenkins Matrix Authorization Strategy Plugin may allow accessing some items

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3