Permission Bypass in Jenkins Config File Provider Plugin by CloudBees
CVE-2021-21645
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 21 April 2021
What is CVE-2021-21645?
The Jenkins Config File Provider Plugin fails to properly enforce permission checks on several HTTP endpoints. Consequently, attackers with Overall/Read permissions can exploit this vulnerability to enumerate the IDs of configuration files, potentially leading to exposure of sensitive information without further authorization.
Affected Version(s)
Jenkins Config File Provider Plugin <= 3.7.0