Unauthorized Credential Enumeration in Jenkins Team Foundation Server Plugin
CVE-2021-21636
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 30 March 2021
What is CVE-2021-21636?
A missing permission check in Jenkins Team Foundation Server Plugin versions 5.157.1 and earlier permits users with Overall/Read permissions to access and enumerate the IDs of stored credentials. This vulnerability exposes sensitive information, making it easier for attackers to exploit user credentials within Jenkins.
Affected Version(s)
Jenkins Team Foundation Server Plugin <= 5.157.1