First published: Wed Apr 07 2021(Updated: )
A flaw was found in Jenkins. Due to lack of validation of the newly created view name, an attackers with View/Create permission are allowed to create views with invalid or already-used names.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <0:2.277.3.1620393611-1.el8 | 0:2.277.3.1620393611-1.el8 |
redhat/jenkins | <0:2.289.1.1624020353-1.el8 | 0:2.289.1.1624020353-1.el8 |
Jenkins Jenkins | <=2.277.1 | |
Jenkins Jenkins | <=2.286 | |
maven/org.jenkins-ci.main:jenkins-core | <2.277.2 | 2.277.2 |
maven/org.jenkins-ci.main:jenkins-core | >=2.278<=2.286 | 2.287 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21640.
The severity of CVE-2021-21640 is medium (severity value: 4).
CVE-2021-21640 is a vulnerability in Jenkins that allows attackers with View/Create permission to create views with invalid or already-used names due to lack of validation of the newly created view name.
CVE-2021-21640 affects Jenkins versions 2.286 and earlier, LTS 2.277.1 and earlier.
To fix CVE-2021-21640, update Jenkins to version 2.287 or LTS 2.277.2 or newer.