CVE-2021-21604: High severity Jenkins Jenkins vulnerability
A flaw was found in jenkins. An attacker with permission to create or configure various objects to inject crafted content into Old Data Monitor can cause the instantiation of potentially unsafe objects once discarded by an administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
Jenkins provides XML REST APIs to configure views, jobs, and other items. When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old Data Monitor. If an administrator discards the old data, some erroneous data submitted to these endpoints may be persisted.
This allows attackers with View/Create, Job/Create, Agent/Create, or their respective /Configure permissions to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects when discarded by an administrator.\n\nJenkins 2.275, LTS 2.263.2 does not record submissions from users in Old Data Monitor anymore.
In case of problems, the Java system properties hudson.util.RobustReflectionConverter.recordFailuresForAdmins and hudson.util.RobustReflectionConverter.recordFailuresForAllAuthentications can be set to true to record configuration data submissions from administrators or all users, partially or completely disabling this fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612433584-1.el7 - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2:2.0.21-1.rhaos4.5.el7 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612434332-1.el7 - Upgrade
Upgrade
redhat/machine-config-daemonto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102050524.p0.git.0.9229406.el7 - Upgrade
Upgrade
redhat/openshift-ansibleto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102031005.p0.git.0.c6839a2.el7 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.5.0-202102051529.p0.git.3612.61b096a.el8 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 0:1.0.0-72.rhaos4.5.giteadfc6b.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.263.3.1612434510-1.el8 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.263.2 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
redhat/jenkins LTSto a version that resolves this vulnerability.Fixed in 2.263.2 - Upgrade
Upgrade
jenkinsto a version that resolves this vulnerability.Fixed in 2.275 - Upgrade
Upgrade
jenkinsto a version that resolves this vulnerability.Fixed in 2.263.2 - Configuration
Set the Java system property hudson.util.RobustReflectionConverter.recordFailuresForAdmins to true to record configuration data submissions from administrators (partially or completely disabling this fix in case of problems).
Jenkins Java system properties hudson.util.RobustReflectionConverter.recordFailuresForAdmins = true - Configuration
Set the Java system property hudson.util.RobustReflectionConverter.recordFailuresForAllAuthentications to true to record configuration data submissions from all users/administrators (partially or completely disabling this fix in case of problems).
Jenkins Java system properties hudson.util.RobustReflectionConverter.recordFailuresForAllAuthentications = true
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-21604?
The severity of CVE-2021-21604 is high.
How can an attacker exploit CVE-2021-21604?
An attacker with permission to create or configure various objects can inject crafted content into Old Data Monitor, causing the instantiation of potentially unsafe objects.
Which versions of Jenkins are affected by CVE-2021-21604?
Jenkins versions 2.274 and earlier LTS 2.263.1 and earlier are affected by CVE-2021-21604.
How can I fix CVE-2021-21604?
To fix CVE-2021-21604, update to Jenkins version 2.275 or Jenkins LTS version 2.263.2.
Where can I find more information about CVE-2021-21604?
You can find more information about CVE-2021-21604 at the following references: [Red Hat Security Advisory RHSA-2021:0423](https://access.redhat.com/errata/RHSA-2021:0423), [CVE-2021-21604](https://access.redhat.com/security/cve/cve-2021-21604), [Red Hat Security Advisory RHSA-2021:0429](https://access.redhat.com/errata/RHSA-2021:0429).