CVE-2021-21670: Medium severity Jenkins Jenkins vulnerability
Incorrect Authorization vulnerability was found in Jenkins. Users with Item/Cancel permission are able to cancel queue items and abort builds of jobs even when they do not have Item/Read permission.
Other sources
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.289.2.1629437819-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.289.2.1628252553-1.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.289.3.1633554819-1.el8 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.300 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.289.2 - Upgrade
Upgrade
redhat/jenkins LTSto a version that resolves this vulnerability.Fixed in 2.289.2 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 2.300 - Upgrade
Upgrade
Jenkinsto a version that resolves this vulnerability.Fixed in 2.300 - Upgrade
Upgrade
Jenkins (LTS)to a version that resolves this vulnerability.Fixed in 2.289.2 - Configuration
As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.
Jenkins Item/Cancel permission assignment = Only to users who also have Item/Read permission
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this Jenkins vulnerability?
The vulnerability ID for this Jenkins vulnerability is CVE-2021-21670.
What is the severity of CVE-2021-21670?
The severity of CVE-2021-21670 is medium.
How does CVE-2021-21670 affect Jenkins?
CVE-2021-21670 allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission, even without Item/Read permission.
How can I fix CVE-2021-21670 in Jenkins?
To fix CVE-2021-21670 in Jenkins, update to version 2.289.2 or later for Jenkins LTS or version 2.300 or later for Jenkins.
Where can I find more information about CVE-2021-21670?
More information about CVE-2021-21670 can be found at the following references: [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2278), [Openwall Mailing List](http://www.openwall.com/lists/oss-security/2021/06/30/1), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2021:3820).