#VU49529 Permissions, Privileges, and Access Controls in Jenkins and Jenkins LTS - CVE-2021-21606

 

#VU49529 Permissions, Privileges, and Access Controls in Jenkins and Jenkins LTS - CVE-2021-21606

Published: January 13, 2021 / Updated: January 14, 2021


Vulnerability identifier: #VU49529
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-21606
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Jenkins
Jenkins LTS
Software vendor:
Jenkins

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to arbitrary file existence check in file fingerprints. A remote authenticated attacker can check for the existence of XML files on the controller file system where the relative path can be constructed as 32 characters.


Remediation

Install updates from vendor's website.

External links