Количество 2
Количество 2
CVE-2021-21625
Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances.
GHSA-jwr9-h4jm-c9ch
Missing permission checks in Jenkins CloudBees AWS Credentials Plugin allows enumerating credentials IDs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-21625 Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances. | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
GHSA-jwr9-h4jm-c9ch Missing permission checks in Jenkins CloudBees AWS Credentials Plugin allows enumerating credentials IDs | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу