PT-2021-14674 · Jenkins · Jenkins Cloud Statistics Plugin+1
Daniel Beck
·
Published
2021-03-30
·
Updated
2023-10-25
·
CVE-2021-21631
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Cloud Statistics Plugin versions 0.26 and earlier
Description
The issue concerns a lack of permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages. This affects users with specific permissions, potentially exposing sensitive information.
Recommendations
For Jenkins Cloud Statistics Plugin versions 0.26 and earlier, update to version 0.27 or later, which requires Overall/Administer permission to access provisioning exception error messages, thus mitigating the issue.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Cloud Statistics Plugin