CVE-2021-21643 PUBLISHED CVSS 4 MEDIUM

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

EPSS 0.83% · 74.5th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.83%
74.5th percentile

Affected Products

VendorProductVersions
Mavenorg.jenkins-ci.plugins:config-file-provider0
Jenkins projectJenkins Config File Provider Pluginunspecified
jenkinsconfig_file_provider0

Timeline

References

Open in Interactive Console →