CVE-2021-21673

MEDIUM6.1EPSS 0.08%

Open redirect vulnerability in Jenkins CAS Plugin

Published: 5/24/2022Modified: 2/16/2024
Also known as:GHSA-2vvr-5757-qp87

Description

Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins. This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication. Jenkins CAS Plugin 1.6.1 only redirects to relative (Jenkins) URLs.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (5)