CVE-2021-21632
Java vulnerability analysis and mitigation

Overview

CVE-2021-21632 is a security vulnerability discovered in the OWASP Dependency-Track Plugin for Jenkins, disclosed on March 30, 2021. The vulnerability affects versions 3.1.0 and earlier of the plugin, where missing permission checks in several HTTP endpoints could allow unauthorized access to sensitive credentials (Jenkins Advisory, OSS Security).

Technical details

The vulnerability stems from improper permission checks implementation in multiple HTTP endpoints of the OWASP Dependency-Track Plugin. The issue is classified with a Medium severity (CVSS) rating. The vulnerability allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, potentially exposing 'Secret text' credentials stored in Jenkins. If no credentials ID is specified, the globally configured credential could be captured if set up (Jenkins Advisory).

Impact

The vulnerability enables attackers with Overall/Read permission to capture sensitive credentials stored in Jenkins. This includes the ability to access 'Secret text' credentials through attacker-specified credentials IDs, as well as the potential to capture globally configured credentials when no specific credentials ID is provided (Jenkins Advisory).

Mitigation and workarounds

The vulnerability has been fixed in OWASP Dependency-Track Plugin version 3.1.1. The updated version implements proper permission checks and requires POST requests for the affected HTTP endpoints. Users are strongly advised to upgrade to this version to address the security issue (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management