CVE Published: 11/05/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Xray - Test Management for Jira Plugin Status : PUBLISHED
CVE-2021-21652 Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.