CVE-2021-21645: Medium severity jenkins config file provider vulnerability
A flaw was found in the config-file-provider Jenkins plugin. The plugin does not perform permission checks in several HTTP endpoints, as a consequence an attacker with Overall/Read permission is allowed to enumerate configuration file IDs.
Other sources
Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to enumerate configuration file IDs.
An enumeration of configuration file IDs in Config File Provider Plugin 3.7.1 requires the appropriate permissions.
— Red Hat
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to enumerate configuration file IDs.
An enumeration of configuration file IDs in Jenkins Config File Provider Plugin 3.7.1 requires the appropriate permissions.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21645.
What is the severity of CVE-2021-21645?
The severity of CVE-2021-21645 is medium with a severity value of 4.3.
What does CVE-2021-21645 affect?
CVE-2021-21645 affects Jenkins Config File Provider Plugin versions 3.7.0 and earlier.
How can an attacker exploit CVE-2021-21645?
An attacker with Overall/Read permission can exploit CVE-2021-21645 to enumerate configuration file IDs.
How can I fix CVE-2021-21645?
To fix CVE-2021-21645, upgrade to Jenkins Config File Provider Plugin version 3.7.1 or later.