SB2021040814 - Multiple vulnerabilities in Jenkins and Jenkins LTS



SB2021040814 - Multiple vulnerabilities in Jenkins and Jenkins LTS

Published: April 8, 2021

Security Bulletin ID SB2021040814
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2021-21639)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected software does not validate the type of object created after loading the data submitted to the "config.xml" REST API endpoint of a node. A remote authenticated attacker can replace a node with one of a different type.


2) Improper Authentication (CVE-ID: CVE-2021-21640)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the affected software does not properly check that a newly created view has an allowed name. A remote authenticated attacker can create views with invalid or already-used names.


Remediation

Install update from vendor's website.