Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade python-ironic-prometheus-exporterUpgrade python-openstacksdkUpgrade openshift-kuryrUpgrade python-hardwareUpgrade jenkins-2-pluginsUpgrade python-oslo-logUpgrade python-oslo-dbUpgrade openshiftUpgrade python-openshiftUpgrade ovn2.13Upgrade butaneUpgrade python-oslo-configUpgrade openshift-ansibleUpgrade atomic-openshift-service-idlerUpgrade python-oslo-i18nUpgrade python-oslo-concurrencyUpgrade python-toozUpgrade ironic-images-ipa-x86_64Upgrade python-eventletUpgrade python-debtcollectorUpgrade podmanUpgrade python-oslo-policyUpgrade jenkinsUpgrade python-jsonschemaUpgrade ostreeUpgrade runcUpgrade python-sushyUpgrade toolboxUpgrade python-pyrsistentUpgrade ironic-images-ipa-ppc64leUpgrade python-kubernetesUpgrade python-stevedoreUpgrade python-ironic-libUpgrade console-login-helper-messagesUpgrade openstack-ironicUpgrade python-oslo-serializationUpgrade python-oslo-utilsUpgrade kata-containersUpgrade ironic-imagesUpgrade openvswitch2.15Upgrade rust-afterburnUpgrade rteval-loadsUpgrade cri-toolsUpgrade coreos-installerUpgrade openshift-clientsUpgrade python-keystoneauth1Upgrade haproxyUpgrade openstack-ironic-inspectorUpgrade python-oslo-serviceUpgrade ignitionUpgrade python-oslo-upgradecheckUpgrade python-sushy-oem-idracUpgrade redhat-release-coreosUpgrade python-oslo-contextUpgrade openstack-ironic-python-agentUpgrade cri-o | Jun 2, 2021 | Apr 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub