First published: Wed Jun 30 2021(Updated: )
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <0:2.289.2.1629437819-1.el8 | 0:2.289.2.1629437819-1.el8 |
redhat/jenkins | <0:2.289.2.1628252553-1.el8 | 0:2.289.2.1628252553-1.el8 |
redhat/jenkins | <0:2.289.3.1633554819-1.el8 | 0:2.289.3.1633554819-1.el8 |
Jenkins Jenkins | >=2.266<2.300 | |
Jenkins Jenkins | >=2.277.1<2.289.2 | |
maven/org.jenkins-ci.main:jenkins-core | <=2.289.1 | 2.289.2 |
maven/org.jenkins-ci.main:jenkins-core | >=2.292<=2.299 | 2.300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-21671 is a vulnerability in Jenkins 2.299 and earlier LTS 2.289.1 and earlier.
CVE-2021-21671 allows attackers to use social engineering techniques to gain administrator access to Jenkins.
The severity of CVE-2021-21671 is high, with a severity value of 7.5.
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier are affected by CVE-2021-21671.
To fix CVE-2021-21671, update to Jenkins 2.300 or LTS 2.289.2 or later.