CVE-2021-21632: Medium severity owasp dependency-track vulnerability
A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
Other sources
Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing \"Secret text\" credentials stored in Jenkins. If no credentials ID is specified, the globally configured credential is used, if set up, and can likewise be captured.
Jenkins OWASP Dependency-Track Plugin 3.1.1 requires appropriate permissions for the affected HTTP endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21632?
CVE-2021-21632 is considered a critical vulnerability due to its potential to expose sensitive credentials.
How do I fix CVE-2021-21632?
To fix CVE-2021-21632, update the Jenkins OWASP Dependency-Track Plugin to version 3.1.1 or later.
Who is affected by CVE-2021-21632?
CVE-2021-21632 affects users of Jenkins with the OWASP Dependency-Track Plugin version 3.1.0 and earlier.
What kind of attack does CVE-2021-21632 facilitate?
CVE-2021-21632 allows attackers to connect to an attacker-specified URL, potentially capturing sensitive credentials.
Is CVE-2021-21632 a zero-day vulnerability?
CVE-2021-21632 is not classified as a zero-day since a fix is available, but it is still critical due to its exploitability.