High severity8.8NVD Advisory· Published Aug 31, 2021· Updated Jun 17, 2026
CVE-2021-21679
CVE-2021-21679
Description
Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:azure-adMaven | < 180.v8b1e80e6f242 | 180.v8b1e80e6f242 |
Affected products
3- Range: 164.v5b48baa961d2
- cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*Range: >=164.v5b48baa961d2,<=179.vf6841393099e
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2021/08/31/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-x77r-7m5w-pqq2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21679ghsaADVISORY
- www.jenkins.io/security/advisory/2021-08-31/nvdVendor AdvisoryWEB
- github.com/jenkinsci/azure-ad-plugin/commit/8b1e80e6f242275127ebb177e2a755a2104b4853ghsaWEB
News mentions
1- Jenkins Security Advisory 2021-08-31Jenkins Security Advisories · Aug 31, 2021