CVE Vulnerabilities

CVE-2021-21670

Published: Jun 30, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins*2.289.2 (excluding)
JenkinsJenkins*2.300 (excluding)
Red Hat OpenShift Container Platform 4.6RedHatjenkins-0:2.289.2.1629437819-1.el8*
Red Hat OpenShift Container Platform 4.7RedHatjenkins-0:2.289.2.1628252553-1.el8*
Red Hat OpenShift Container Platform 4.8RedHatjenkins-0:2.289.3.1633554819-1.el8*

References