CVE-2021-21671
Summary
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- HIGH
References
Advisory Timeline
- Published
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.