Medium severity4.3NVD Advisory· Published Mar 18, 2021· Updated Jun 17, 2026
CVE-2021-21626
CVE-2021-21626
Description
Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.jenkins.plugins:warnings-ngMaven | < 8.5.0 | 8.5.0 |
Affected products
2- Range: unspecified
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2021/03/18/5nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-7j3x-xm4j-jfj7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21626ghsaADVISORY
- www.jenkins.io/security/advisory/2021-03-18/nvdVendor AdvisoryWEB
News mentions
1- Jenkins Security Advisory 2021-03-18Jenkins Security Advisories · Mar 18, 2021