VYPR
Medium severity4.3NVD Advisory· Published Mar 30, 2021· Updated Jun 17, 2026

CVE-2021-21631

CVE-2021-21631

Description

Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:cloud-statsMaven
< 0.270.27

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

1