CVE-2021-21643
21.04.2021, 15:15
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | config_file_provider | 𝑥 ≤ 3.7.0 |
𝑥
= Vulnerable software versions