Security Advisory

CVE-2021-21609

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-01-13 15:55:31
Last updated 2024-08-03 18:16:23
Assigner jenkins
CVSS score not scored
State PUBLISHED

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.