CVE-2021-21661

Severity
4.3MEDIUM
EPSS
0.4%
top 37.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateJun 16

Description

Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Missing Authorization in Jenkins Kubernetes CLI Plugin2021-06-16
OSV
Missing Authorization in Jenkins Kubernetes CLI Plugin2021-06-16
CVEList
CVE-2021-21661: Jenkins Kubernetes CLI Plugin 12021-06-10

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2021-06-102021-06-10
CVE-2021-21661 (MEDIUM CVSS 4.3) | Jenkins Kubernetes CLI Plugin 1.10. | cvebase.io