CVE-2021-21671Session Fixation in Project Jenkins

CWE-384Session Fixation6 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 49.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateMay 24

Description

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

NVDjenkins/jenkins2.2662.300+1
CVEListV5jenkins_project/jenkins2.266unspecified+3

🔴Vulnerability Details

3
OSV
Session fixation vulnerability in Jenkins2022-05-24
GHSA
Session fixation vulnerability in Jenkins2022-05-24
CVEList
CVE-2021-21671: Jenkins 22021-06-30

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2021-06-302021-06-30
Red Hat
jenkins: session fixation vulnerability2021-06-30
CVE-2021-21671 — Session Fixation in Project Jenkins | cvebase