Jenkins Role-based Authorization Strategy Plugin Vulnerability
CVE-2021-21624
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 18 March 2021
What is CVE-2021-21624?
The Jenkins Role-based Authorization Strategy Plugin contains a flaw that allows attackers with Item/Read permission on nested items to bypass permissions. This vulnerability arises when the permission checks do not enforce access controls correctly, enabling unauthorized access to nested items despite lacking the necessary permissions for parent folders. This misconfiguration could lead to sensitive data exposure if exploited.
Affected Version(s)
Jenkins Role-based Authorization Strategy Plugin <= 3.1