CVE Vulnerabilities

CVE-2021-21671

Published: Jun 30, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

Affected Software

NameVendorStart VersionEnd Version
JenkinsJenkins2.266 (including)2.300 (excluding)
JenkinsJenkins2.277.1 (including)2.289.2 (excluding)
Red Hat OpenShift Container Platform 4.6RedHatjenkins-0:2.289.2.1629437819-1.el8*
Red Hat OpenShift Container Platform 4.7RedHatjenkins-0:2.289.2.1628252553-1.el8*
Red Hat OpenShift Container Platform 4.8RedHatjenkins-0:2.289.3.1633554819-1.el8*

References