Lucene search

K
osvGoogleOSV:CVE-2021-21637
HistoryMar 30, 2021 - 12:16 p.m.

CVE-2021-21637

2021-03-3012:16:10
Google
osv.dev
5
jenkins
team foundation server
permission check
attackers
credentials

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

28.4%

A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

28.4%