CVE-2021-21638: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21638?
CVE-2021-21638 is a cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier.
How does CVE-2021-21638 work?
CVE-2021-21638 allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
What software versions are affected by CVE-2021-21638?
Jenkins Team Foundation Server Plugin versions up to and including 5.157.1 are affected.
How severe is CVE-2021-21638?
CVE-2021-21638 has a severity rating of 8.8 (high).
How can I fix CVE-2021-21638?
To fix CVE-2021-21638, it is recommended to upgrade Jenkins Team Foundation Server Plugin to a version beyond 5.157.1.