CVE-2021-21654
published 2021-05-11CVE-2021-21654: Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect…
medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials_plugin | — | — |
| jenkins | dashboard_view_plugin | — | — |
| jenkins | ids_in_xray_test_management_for_jira_plugin | — | — |
| jenkins | p4 | <= 1.11.4 | — |
| jenkins | p4_plugin | — | — |
| jenkins | s3_publisher_plugin | — | — |
| jenkins | xcode_integration_plugin | — | — |
| jenkins | xray_test_management_for_jira_plugin | — | — |
| jenkins_project | jenkins_p4_plugin | unspecified – 1.11.4 | — |