Jenkins Role-based Authorization Strategy Plugin Vulnerability
CVE-2021-21624
4.3MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 18 March 2021
Summary
The Jenkins Role-based Authorization Strategy Plugin contains a flaw that allows attackers with Item/Read permission on nested items to bypass permissions. This vulnerability arises when the permission checks do not enforce access controls correctly, enabling unauthorized access to nested items despite lacking the necessary permissions for parent folders. This misconfiguration could lead to sensitive data exposure if exploited.
Affected Version(s)
Jenkins Role-based Authorization Strategy Plugin <= 3.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved