Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5859 Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
Github GHSA Github GHSA GHSA-xv69-6rf3-w5g2 Missing permission check in Jenkins Cloud Statistics Plugin
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-03T18:16:23.849Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-30T12:16:10.470

Modified: 2024-11-21T05:48:43.960

Link: CVE-2021-21631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.