Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21645

Опубликовано: 21 апр. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.

A flaw was found in the config-file-provider Jenkins plugin. The plugin does not perform permission checks in several HTTP endpoints, as a consequence an attacker with Overall/Read permission is allowed to enumerate configuration file IDs.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=1952152jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints.

EPSS

Процентиль: 32%
0.00118
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.

CVSS3: 4.3
github
около 3 лет назад

Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDs

EPSS

Процентиль: 32%
0.00118
Низкий

4.3 Medium

CVSS3