Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21643

Опубликовано: 21 апр. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

A flaw was found in the config-file-provider Jenkins plugin. The plugin does not correctly perform permission checks in several HTTP endpoints, as a consequence an attacker with global Job/Configure permission can enumerate system-scoped credentials IDs of credentials stored in Jenkins.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=1952148jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints.

EPSS

Процентиль: 74%
0.00832
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 5 лет назад

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

CVSS3: 6.5
github
больше 3 лет назад

Incorrect permission checks in Jenkins Config File Provider Plugin allow enumerating credentials IDs

EPSS

Процентиль: 74%
0.00832
Низкий

4.3 Medium

CVSS3