CVE-2021-21621

MEDIUM

Jenkins Support Core Plugin < 2.72 - Exposure of Sensitive Information via Serialized User Authentication

Title source: llm
STIX 2.1

Description

Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating the support bundle in some configurations.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
jenkins/support_core < 2.72
org.jenkins-ci.plugins/support-core 0 - 2.72.1Maven
Published Feb 24, 2021
Tracked Since Feb 18, 2026