Lucene search

K
cvelistJenkinsCVELIST:CVE-2021-21624
HistoryMar 18, 2021 - 1:35 p.m.

CVE-2021-21624

2021-03-1813:35:22
jenkins
www.cve.org
2

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

22.0%

An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

CNA Affected

[
  {
    "product": "Jenkins Role-based Authorization Strategy Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "3.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for CVELIST:CVE-2021-21624