CVE-2021-21679

HIGH

Jenkins Azure AD Plugin < 179.vf6841393099e - Cross-Site Request Forgery Protection Bypass

Title source: llm
STIX 2.1

Description

Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/08/31/1

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (2)
jenkins/azure_ad 164.v5b48baa961d2 - 179.vf6841393099e
org.jenkins-ci.plugins/azure-ad 0 - 180.v8b1e80e6f242Maven
Published Aug 31, 2021
Tracked Since Feb 18, 2026