CVE-2021-21681 affects Jenkins Nomad Plugin versions 0.7.4 and earlier, where Docker passwords are stored unencrypted in the global config.xml file on the Jenkins controller. This vulnerability has a CVSS score of 5.5 (Medium), indicating that a local attacker with low privileges can access sensitive information, specifically Docker passwords, from the file system. While the potential impact is a high compromise of confidentiality, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.4CPE matchmatch criteria | cpe:2.3:a:jenkins:nomad:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.