CVE-2021-21645

Source
https://cve.org/CVERecord?id=CVE-2021-21645
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21645.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-21645
Aliases
Downstream
Published
2021-04-21T15:15:08.407Z
Modified
2026-02-07T05:14:19.564844Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.

References

Affected packages

Git / github.com/jenkinsci/config-file-provider-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/config-file-provider-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1002.*
1002.v93e06b_792d44
1006.*
1006.vc7366c201f57
2.*
2.8.1
938.*
938.ve2b_8a_591c596
951.*
951.953.vdfc5f6e2dcc4
951.v0461b_87b_721b_
952.*
952.va_544a_6234b_46
953.*
953.v0432a_802e4d2
959.*
959.vcff671a_4518b_
968.*
968.ve1ca_eb_913f8c
973.*
973.vb_a_80ecb_9a_4d0
978.*
978.v8e85886ffdc4
980.*
980.v88956a_a_5d6a_d
982.*
982.vb_a_e458a_37021
988.*
988.v0461fcc2b_9d1
994.*
994.v3d4a_5fa_f353a_
config-file-provider-1.*
config-file-provider-1.0
config-file-provider-1.1
config-file-provider-1.2
config-file-provider-1.4
config-file-provider-1.5
config-file-provider-1.6
config-file-provider-1.6.1
config-file-provider-1.9.1
config-file-provider-2.*
config-file-provider-2.0
config-file-provider-2.1
config-file-provider-2.1.1
config-file-provider-2.10.0
config-file-provider-2.10.1
config-file-provider-2.11
config-file-provider-2.12
config-file-provider-2.13
config-file-provider-2.14-beta
config-file-provider-2.14.1-beta
config-file-provider-2.14.2-beta
config-file-provider-2.15
config-file-provider-2.15.1
config-file-provider-2.15.2-beta
config-file-provider-2.15.3
config-file-provider-2.15.3-beta
config-file-provider-2.15.4
config-file-provider-2.15.5
config-file-provider-2.15.6
config-file-provider-2.15.7
config-file-provider-2.16.0
config-file-provider-2.16.1
config-file-provider-2.16.2
config-file-provider-2.16.3
config-file-provider-2.16.4
config-file-provider-2.17
config-file-provider-2.18
config-file-provider-2.2.1
config-file-provider-2.3
config-file-provider-2.4
config-file-provider-2.5
config-file-provider-2.5.1
config-file-provider-2.6
config-file-provider-2.6.1
config-file-provider-2.6.2
config-file-provider-2.7
config-file-provider-2.7.1
config-file-provider-2.7.2
config-file-provider-2.7.3
config-file-provider-2.7.4
config-file-provider-2.7.5
config-file-provider-2.9.1
config-file-provider-2.9.2
config-file-provider-2.9.3
config-file-provider-3.*
config-file-provider-3.0
config-file-provider-3.1
config-file-provider-3.10.0
config-file-provider-3.11
config-file-provider-3.11.0
config-file-provider-3.11.1
config-file-provider-3.2
config-file-provider-3.3
config-file-provider-3.4
config-file-provider-3.4.1
config-file-provider-3.5
config-file-provider-3.6
config-file-provider-3.6.1
config-file-provider-3.6.2
config-file-provider-3.6.3
config-file-provider-3.7.0
config-file-provider-3.7.1
config-file-provider-3.8.0
config-file-provider-3.8.1
config-file-provider-3.8.2
config-file-provider-3.9.0
config-provider-model-1.*
config-provider-model-1.0
config-provider-model-1.1
config-provider-model-1.2
config-provider-model-1.3
config-provider-model-1.3.1
config-provider-model-1.3.2
config-provider-model-1.3.3
config-provider-model-1.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21645.json"