← Back to CVE List

CVE-2021-21643

Published: 2021-04-21T15:15Z
Last Modified: 2024-11-21T05:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt