Jenkins Warnings Next Generation Plugin File Pattern Disclosure Vulnerability
CVE-2021-21626
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 18 March 2021
What is CVE-2021-21626?
The Warnings Next Generation Plugin in Jenkins versions 8.4.4 and earlier contains a permission check flaw. This vulnerability allows an attacker with Item/Read permission to validate attacker-specified file patterns against contents in the workspace without the necessary Item/Workspace or Item/Configure permissions. This could potentially lead to the leakage of sensitive information related to the workspace files and patterns.
Affected Version(s)
Jenkins Warnings Next Generation Plugin <= 8.4.4
Jenkins Warnings Next Generation Plugin 8.4.3.1