CVE-2021-21644

Severity
5.4MEDIUM
EPSS
0.1%
top 68.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 21
Latest updateMay 24

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files2022-05-24
OSV
CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files2022-05-24
CVEList
CVE-2021-21644: A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 32021-04-21

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2021-04-212021-04-21
Red Hat
jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.2021-04-21
CVE-2021-21644 (MEDIUM CVSS 5.4) | A cross-site request forgery (CSRF) | cvebase.io