CVE-2021-21644: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
Other sources
A cross-site request forgery (CSRF) vulnerability was found in the config-file-provider Jenkins plugin. The plugin does not require POST requests for an HTTP endpoint which allows attackers to delete configuration files corresponding to an attacker-specified ID.
Config File Provider Plugin 3.7.0 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to delete configuration files corresponding to an attacker-specified ID.
This is due to an incomplete fix of https://www.jenkins.io/security/advisory/2018-09-25/#SECURITY-938
— Red Hat
Jenkins Config File Provider Plugin 3.7.0 and earlier does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to delete configuration files corresponding to an attacker-specified ID.
This is due to an incomplete fix of SECURITY-938.
Jenkins Config File Provider Plugin 3.7.1 requires POST requests for the affected HTTP endpoint.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-21644?
CVE-2021-21644 is a cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier.
How severe is CVE-2021-21644?
CVE-2021-21644 has a severity of 6.3 (medium).
How does CVE-2021-21644 affect Jenkins Config File Provider Plugin?
CVE-2021-21644 allows attackers to delete configuration files corresponding to an attacker-specified ID.
What is the remedy for CVE-2021-21644 in Jenkins Config File Provider Plugin?
The remedy for CVE-2021-21644 in Jenkins Config File Provider Plugin is to update to version 3.7.1 or later.
Where can I find more information about CVE-2021-21644?
More information about CVE-2021-21644 can be found at the following references: [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2018-09-25/#SECURITY-938), [Red Hat Errata](https://access.redhat.com/errata/RHSA-2021:2122), [Red Hat CVE](https://access.redhat.com/security/cve/cve-2021-21644)