PT-2021-14683 · Jenkins · Jenkins
Jeff Thompson
·
Published
2021-04-07
·
Updated
2024-03-06
·
CVE-2021-21640
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.286 and earlier
Jenkins LTS versions 2.277.1 and earlier
Description
The issue arises from the improper validation of newly created view names, allowing attackers with View/Create permission to create views with invalid or already-used names. This occurs because when a form to create a view is submitted, the name is included twice, with one instance being validated and the other instance being used for view creation. This discrepancy enables the creation of views with names that should be restricted.
Recommendations
For Jenkins versions 2.286 and earlier, update to version 2.287 or later to resolve the issue.
For Jenkins LTS versions 2.277.1 and earlier, update to version 2.277.2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins