High severityNVD Advisory· Published Aug 31, 2021· Updated Aug 3, 2024
CVE-2021-21678
CVE-2021-21678
Description
Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:samlMaven | < 2.0.8 | 2.0.8 |
Affected products
2- Range: 1.1.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-r5w3-pfq8-3r82ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21678ghsaADVISORY
- www.openwall.com/lists/oss-security/2021/08/31/1ghsamailing-listx_refsource_MLISTWEB
- github.com/jenkinsci/saml-plugin/commit/e063317ee7e1c64a096e0ac323c7155b786c8b9dghsaWEB
- www.jenkins.io/security/advisory/2021-08-31/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2021-08-31Jenkins Security Advisories · Aug 31, 2021