CVE-2021-21639: Input Validation
A flaw was found in Jenkins. Due to lack of validation of type of object created after loading the data submitted to the config.xml REST API endpoint of a node, an attackers with Computer/Configure permission are able to replace a node with one of a different type.
Other sources
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the config.xml REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type.
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the config.xml REST API endpoint of a node.
This allows attackers with Computer/Configure permission to replace a node with one of a different type.
Jenkins 2.287, LTS 2.277.2 validates the type of object created and rejects objects of unexpected types.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.277.3.1620393611-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.289.1.1624020353-1.el8 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.277.2 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.287 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2.287 - Upgrade
Upgrade
redhat/jenkins LTSto a version that resolves this vulnerability.Fixed in 2.277.2 - Upgrade
Upgrade
Jenkinsto a version that resolves this vulnerability.Fixed in 2.287 - Upgrade
Upgrade
Jenkins LTSto a version that resolves this vulnerability.Fixed in 2.277.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-21639?
CVE-2021-21639 is a vulnerability in Jenkins that allows attackers with Computer/Configure permission to replace a node with one of a different type.
What is the severity of CVE-2021-21639?
CVE-2021-21639 has a severity rating of 3.1 (low).
How does CVE-2021-21639 affect Jenkins?
CVE-2021-21639 affects Jenkins versions 2.286 and earlier, LTS 2.277.1 and earlier.
How can I fix CVE-2021-21639?
To fix CVE-2021-21639, update Jenkins to version 2.287 or LTS 2.277.2 or later.
Where can I find more information about CVE-2021-21639?
More information about CVE-2021-21639 can be found at the following references: [1](http://www.openwall.com/lists/oss-security/2021/04/07/2), [2](https://www.jenkins.io/security/advisory/2021-04-07/#SECURITY-1721), [3](https://access.redhat.com/errata/RHSA-2021:2437).