Description
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1948 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs. |
Github GHSA |
GHSA-2959-fj73-hm8p | Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDs |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.825Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21645
No data.
Status : Modified
Published: 2021-04-21T15:15:08.407
Modified: 2024-11-21T05:48:45.570
Link: CVE-2021-21645
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA