PT-2021-14719 · Jenkins · Jenkins+1

Matt Sicker

·

Published

2021-06-30

·

Updated

2023-11-22

·

CVE-2021-21676

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins requests-plugin Plugin versions 2.2.7 and earlier
Description The issue is related to a missing permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address. This affects versions of the Jenkins requests-plugin Plugin prior to version 2.2.8, which now requires Overall/Administer permission to send test emails.
Recommendations For Jenkins requests-plugin Plugin versions 2.2.7 and earlier, update to version 2.2.8 or later, which requires Overall/Administer permission to send test emails, mitigating the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-21676
GHSA-W3GM-VV58-WR55

Affected Products

Jenkins
Requests-Plugin