Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21670

Опубликовано: 30 июн. 2021
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

Incorrect Authorization vulnerability was found in Jenkins. Users with Item/Cancel permission are able to cancel queue items and abort builds of jobs even when they do not have Item/Read permission.

Меры по смягчению последствий

As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jenkinsNot affected
Red Hat OpenShift Container Platform 3.11jenkinsWill not fix
Red Hat OpenShift Container Platform 4.6jenkinsFixedRHBA-2021:339608.09.2021
Red Hat OpenShift Container Platform 4.7jenkinsFixedRHBA-2021:303317.08.2021
Red Hat OpenShift Container Platform 4.8jenkinsFixedRHSA-2021:382019.10.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2007749jenkins: improper permission checks allow canceling queue items and aborting builds

EPSS

Процентиль: 78%
0.01173
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

CVSS3: 4.3
debian
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to can ...

CVSS3: 4.3
github
больше 3 лет назад

Improper permission checks allow canceling queue items and aborting builds in Jenkins

EPSS

Процентиль: 78%
0.01173
Низкий

4.3 Medium

CVSS3