PT-2021-14690 · Cloudbees+1 · Jenkins Cloudbees Cd Plugin+1

Devin Nusbaum

·

Published

2021-04-21

·

Updated

2023-10-25

·

CVE-2021-21647

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins CloudBees CD Plugin versions 1.1.21 and earlier
Description The issue concerns a lack of permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission. This affects the scheduling of builds via the HTTP endpoint, which requires Item/Build permission.
Recommendations For Jenkins CloudBees CD Plugin versions 1.1.21 and earlier, consider restricting access to the HTTP endpoint to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that only users with Item/Build permission can schedule builds of projects.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-21647
GHSA-7RX6-4VWV-432G

Affected Products

Jenkins
Jenkins Cloudbees Cd Plugin