CVE-2021-21671

HIGH

Jenkins < 2.300, LTS < 2.289.2 - Session Fixation

Title source: llm
STIX 2.1

Description

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/06/30/1

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
jenkins/jenkins 2.266 - 2.300
jenkins/jenkins 2.277.1 - 2.289.2
org.jenkins-ci.main/jenkins-core 2.292 - 2.300Maven
Published Jun 30, 2021
Tracked Since Feb 18, 2026