Description
Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5736 | Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. |
Github GHSA |
GHSA-x77r-7m5w-pqq2 | Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:23:29.177Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21679
No data.
Status : Modified
Published: 2021-08-31T14:15:25.553
Modified: 2026-06-17T03:35:59.057
Link: CVE-2021-21679
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-352
Cross-Site Request Forgery (CSRF)
EUVD
Github GHSA