CVE-2021-21621
CVE-2021-21621
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Feb 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating the support bundle in some configurations.
Affected products
Jenkins project · Jenkins Support Core PluginWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →