CVE-2021-21661
published 2021-06-10CVE-2021-21661: Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EXPLOIT
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | ids_in_kubernetes_cli_plugin | — | — |
| jenkins | ids_in_xebialabs_xl_deploy_plugin | — | — |
| jenkins | kiuwan_plugin | — | — |
| jenkins | kubernetes | <= 1.10.0 | — |
| jenkins | kubernetes_cli_plugin | — | — |
| jenkins | xebialabs_xl_deploy_plugin | — | — |
| jenkins_project | jenkins_kubernetes_cli_plugin | unspecified – 1.10.0 | — |