CVE-2021-21647: Medium severity cloudbees jenkins vulnerability
Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.
Other sources
Jenkins CloudBees CD Plugin does not perform a permission check in an HTTP endpoint.
This allows attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.
Jenkins CloudBees CD Plugin requires Item/Build permission to schedule builds via its HTTP endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21647?
The severity of CVE-2021-21647 is medium with a severity value of 4.3.
How does CVE-2021-21647 affect Jenkins CloudBees CD Plugin?
CVE-2021-21647 allows attackers with Item/Read permission to schedule builds of projects without having Item/Build permission in Jenkins CloudBees CD Plugin.
What is the remedy for CVE-2021-21647?
The remedy for CVE-2021-21647 is to update Jenkins CloudBees CD Plugin to version 1.1.22.
Where can I find more information about CVE-2021-21647?
You can find more information about CVE-2021-21647 on the NIST National Vulnerability Database (NVD) website and the Jenkins security advisory.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-21647?
The CWE ID for CVE-2021-21647 is 862.