CVE Vulnerabilities

CVE-2021-21671

Published: Jun 30, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

Affected Software

Name Vendor Start Version End Version
Jenkins Jenkins 2.266 (including) 2.300 (excluding)
Jenkins Jenkins 2.277.1 (including) 2.289.2 (excluding)
Red Hat OpenShift Container Platform 4.6 RedHat jenkins-0:2.289.2.1629437819-1.el8 *
Red Hat OpenShift Container Platform 4.7 RedHat jenkins-0:2.289.2.1628252553-1.el8 *
Red Hat OpenShift Container Platform 4.8 RedHat jenkins-0:2.289.3.1633554819-1.el8 *

References