CVE Published: 30/06/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins CAS Plugin Status : PUBLISHED
CVE-2021-21673 Description
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.