CVE-2021-21637: Medium severity microsoft team foundation server vulnerability
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21637?
CVE-2021-21637 is a vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier that allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
How severe is CVE-2021-21637?
CVE-2021-21637 has a severity rating of 6.5 out of 10, which is considered medium.
What software versions are affected by CVE-2021-21637?
Jenkins Team Foundation Server Plugin versions up to and including 5.157.1 are affected by CVE-2021-21637.
How can an attacker exploit CVE-2021-21637?
An attacker with Overall/Read permission can exploit CVE-2021-21637 by connecting to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Are there any references for CVE-2021-21637?
Yes, you can find more information about CVE-2021-21637 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2021/03/30/1), [Reference 2](https://www.jenkins.io/security/advisory/2021-03-30/#SECURITY-2283%20(2))