CVE-2021-21661: Medium severity jenkins kubernetes ci vulnerability
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21661?
CVE-2021-21661 has a medium severity rating due to the unauthorized enumeration of credential IDs.
How do I fix CVE-2021-21661?
To fix CVE-2021-21661, upgrade the Jenkins Kubernetes CLI Plugin to version 1.10.1 or later.
What are the potential impacts of CVE-2021-21661?
The impact of CVE-2021-21661 includes the risk of exposing sensitive credential IDs to unauthorized users with read permissions.
Which versions are affected by CVE-2021-21661?
CVE-2021-21661 affects all versions of the Jenkins Kubernetes CLI Plugin up to and including 1.10.0.
Who is at risk from CVE-2021-21661?
Users with Overall/Read permission in Jenkins are at risk due to the lack of permission checks in the affected plugin.