CVE-2021-21639 Information

Description

Jenkins 2.286 and earlier LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the config.xml REST API endpoint of a node allowing attackers with Computer/Configure permission to replace a node with one of a different type.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://www.jenkins.io/security/advisory/2021-04-07/#SECURITY-1721 http://www.openwall.com/lists/oss-security/2021/04/07/2

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: