CVE-2021-21654: Medium severity jenkins vulnerability
Published May 11, 2021
·Updated
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:p4<=1.11.4
1.11.5
Jenkins P4 Jenkins<=1.11.4
Event History
May 11, 2021
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
Description
Jun 16, 2021
Advisory Published
05:29 PM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-21654.
2
What is the severity of CVE-2021-21654?
The severity of CVE-2021-21654 is medium, with a severity value of 4.3.
3
What is the affected software of CVE-2021-21654?
The affected software of CVE-2021-21654 is Jenkins P4 Plugin 1.11.4 and earlier.
4
How does CVE-2021-21654 affect the affected software?
CVE-2021-21654 allows attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
5
What is the fix for CVE-2021-21654?
The fix for CVE-2021-21654 is to upgrade to Jenkins P4 Plugin version 1.11.5 or later.