CVE-2021-21645
21.04.2021, 15:15
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | config_file_provider | 𝑥 ≤ 3.7.0 |
𝑥
= Vulnerable software versions