{
  "threat_severity" : "Moderate",
  "public_date" : "2021-04-21T00:00:00Z",
  "bugzilla" : {
    "description" : "jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints.",
    "id" : "1952148",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1952148"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-281",
  "details" : [ "Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.", "A flaw was found in the config-file-provider Jenkins plugin. The plugin does not correctly perform permission checks in several HTTP endpoints, as a consequence an attacker with global Job/Configure permission can enumerate system-scoped credentials IDs of credentials stored in Jenkins." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-controller-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-operator-bundle:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-registry-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-ui-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-rhel8:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-velero-plugin-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "release_date" : "2021-06-30T00:00:00Z",
    "advisory" : "RHSA-2021:2517",
    "cpe" : "cpe:/a:redhat:openshift:3.11::el7",
    "package" : "jenkins-2-plugins-0:3.11.1624366838-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.5",
    "release_date" : "2021-07-02T00:00:00Z",
    "advisory" : "RHSA-2021:2431",
    "cpe" : "cpe:/a:redhat:openshift:4.5::el7",
    "package" : "jenkins-2-plugins-0:4.5.1623326336-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.6",
    "release_date" : "2021-06-22T00:00:00Z",
    "advisory" : "RHBA-2021:2407",
    "cpe" : "cpe:/a:redhat:openshift:4.6::el8",
    "package" : "jenkins-2-plugins-0:4.6.1623162648-1.el8"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.7",
    "release_date" : "2021-06-01T00:00:00Z",
    "advisory" : "RHSA-2021:2122",
    "cpe" : "cpe:/a:redhat:openshift:4.7::el7",
    "package" : "cri-o-0:1.20.2-12.rhaos4.7.git9f7be76.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.7",
    "release_date" : "2021-06-01T00:00:00Z",
    "advisory" : "RHSA-2021:2122",
    "cpe" : "cpe:/a:redhat:openshift:4.7::el7",
    "package" : "cri-tools-0:1.20.0-3.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.7",
    "release_date" : "2021-06-01T00:00:00Z",
    "advisory" : "RHSA-2021:2122",
    "cpe" : "cpe:/a:redhat:openshift:4.7::el7",
    "package" : "jenkins-2-plugins-0:4.7.1621361158-1.el8"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.7",
    "release_date" : "2021-06-01T00:00:00Z",
    "advisory" : "RHSA-2021:2122",
    "cpe" : "cpe:/a:redhat:openshift:4.7::el7",
    "package" : "redhat-release-coreos-0:47.83-2.el8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2021-21643\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-21643\nhttps://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2254" ],
  "name" : "CVE-2021-21643",
  "csaw" : false
}