PT-2021-14683 · Jenkins · Jenkins

Jeff Thompson

·

Published

2021-04-07

·

Updated

2024-03-06

·

CVE-2021-21640

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.286 and earlier Jenkins LTS versions 2.277.1 and earlier
Description The issue arises from the improper validation of newly created view names, allowing attackers with View/Create permission to create views with invalid or already-used names. This occurs because when a form to create a view is submitted, the name is included twice, with one instance being validated and the other instance being used for view creation. This discrepancy enables the creation of views with names that should be restricted.
Recommendations For Jenkins versions 2.286 and earlier, update to version 2.287 or later to resolve the issue. For Jenkins LTS versions 2.277.1 and earlier, update to version 2.277.2 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2021-21640
CVE-2021-21640
GHSA-W2HV-RCQR-2H7R
RHSA-2021:1551
RHSA-2021:2437

Affected Products

Jenkins