CVE-2021-21623Incorrect Authorization in Project Jenkins Matrix Authorization Strategy Plugin

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 72.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
OSV
Incorrect permission checks in Jenkins Matrix Authorization Strategy Plugin may allow accessing some items2022-05-24
GHSA
Incorrect permission checks in Jenkins Matrix Authorization Strategy Plugin may allow accessing some items2022-05-24

📋Vendor Advisories

2
Red Hat
jenkins-2-plugins/matrix-auth: Incorrect permission checks in Matrix Authorization Strategy Plugin2021-03-18
Jenkins
Jenkins Security Advisory 2021-03-182021-03-18