Incorrect Permission Check in Jenkins Matrix Authorization Strategy Plugin Allows Unauthorized Access to Nested Items

Incorrect Permission Check in Jenkins Matrix Authorization Strategy Plugin Allows Unauthorized Access to Nested Items

CVE-2021-21623 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

Learn more about our Web Application Penetration Testing UK.