AWS Credentials Enumeration in CloudBees Plugin by Jenkins
CVE-2021-21625
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 18 March 2021
What is CVE-2021-21625?
The AWS Credentials Plugin for Jenkins allows attackers with Overall/Read permissions to exploit a lack of permission checks in HTTP endpoints. This vulnerability can lead to sensitive information being disclosed, enabling unauthorized users to enumerate AWS credential IDs stored in Jenkins. Proper validation is necessary to secure endpoints against exploitation.
Affected Version(s)
Jenkins CloudBees AWS Credentials Plugin <= 1.28