CVE Vulnerabilities

CVE-2021-21643

Published: Apr 21, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

Affected Software

NameVendorStart VersionEnd Version
Config_file_providerJenkins*3.7.0 (including)
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-controller-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-operator-bundle:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-registry-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-ui-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-velero-plugin-rhel8:v1.4.6-4*
Red Hat OpenShift Container Platform 3.11RedHatjenkins-2-plugins-0:3.11.1624366838-1.el7*
Red Hat OpenShift Container Platform 4.5RedHatjenkins-2-plugins-0:4.5.1623326336-1.el7*
Red Hat OpenShift Container Platform 4.6RedHatjenkins-2-plugins-0:4.6.1623162648-1.el8*
Red Hat OpenShift Container Platform 4.7RedHatcri-o-0:1.20.2-12.rhaos4.7.git9f7be76.el7*
Red Hat OpenShift Container Platform 4.7RedHatcri-tools-0:1.20.0-3.el7*
Red Hat OpenShift Container Platform 4.7RedHatjenkins-2-plugins-0:4.7.1621361158-1.el8*
Red Hat OpenShift Container Platform 4.7RedHatredhat-release-coreos-0:47.83-2.el8*

References