CVE-2021-21631
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
Affected products
Jenkins project · Jenkins Cloud Statistics Plugin