CVE-2021-21621
Support bundles can include user session IDs in Jenkins Support Core Plugin
Description
Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the \"About user (basic authentication details only)\" information (`user.md`). In some configurations, this can include the session ID of the user creating the support bundle. Attackers with access to support bundle content and the Jenkins instance could use this information to impersonate the user who created the support bundle. Support Core Plugin 2.72.1 no longer provides the serialized user authentication as part of the \"About user (basic authentication details only)\" information. As a workaround, deselecting \"About user (basic authentication details only)\" before creating a support bundle will exclude the affected information from the bundle.
How to fix CVE-2021-21621
To remediate CVE-2021-21621, upgrade the affected package to a fixed version below.
- —upgrade to 2.72.1 or later
Is CVE-2021-21621 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.72.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |