CVE-2021-21661
Description
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CWE
- (none)
Affected
- Jenkins project / Jenkins Kubernetes CLI Plugin — v=unspecified ≤1.10.0 [affected]
CVSS
- (none)
References
- https://www.jenkins.io/security/advisory/2021-06-10/#SECURITY-2370 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2021/06/10/14 mailing-list, x_refsource_MLIST
Source
cvelistV5-main/cves/2021/21xxx/CVE-2021-21661.json