CVE-2021-21643

Publication date

2021-04-21 14:20:28

Family

jenkins

State

PUBLISHED

Description

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.