CVE-2021-21655: CSRF
Published May 11, 2021
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:p4<1.11.5
1.11.5
Jenkins P4 Jenkins<=1.11.4
Event History
May 11, 2021
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
Description
Mar 18, 2022
Advisory Published
05:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-21655?
CVE-2021-21655 is classified as a moderate severity vulnerability due to its potential impact on authentication and access control.
2
How do I fix CVE-2021-21655?
To fix CVE-2021-21655, upgrade the Jenkins P4 Plugin to version 1.11.5 or later.
3
What type of vulnerability is CVE-2021-21655?
CVE-2021-21655 is a cross-site request forgery (CSRF) vulnerability.
4
Which versions of Jenkins P4 Plugin are affected by CVE-2021-21655?
Versions 1.11.4 and earlier of the Jenkins P4 Plugin are affected by CVE-2021-21655.
5
What can attackers do with CVE-2021-21655?
Attackers can exploit CVE-2021-21655 to connect to an attacker-specified Perforce server using an attacker-defined username and password.