CVE-2021-21627: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains.
Other sources
Jenkins Libvirt Agents Plugin 1.9.0 and earlier does not require POST requests for a form submission endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to stop hypervisor domains.
Jenkins Libvirt Agents Plugin 1.9.1 requires POST requests for the affected HTTP endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21627?
CVE-2021-21627 is classified as a moderate-severity cross-site request forgery vulnerability.
How do I fix CVE-2021-21627?
To fix CVE-2021-21627, upgrade to Jenkins Libvirt Agents Plugin version 1.9.1 or later.
What versions are affected by CVE-2021-21627?
CVE-2021-21627 affects Jenkins Libvirt Agents Plugin version 1.9.0 and earlier.
What type of vulnerability is CVE-2021-21627?
CVE-2021-21627 is a cross-site request forgery (CSRF) vulnerability.
What actions can be exploited in CVE-2021-21627?
CVE-2021-21627 can be exploited to stop hypervisor domains without requiring POST requests.