PT-2021-14708 · Xebialabs+1 · Jenkins Xebialabs Xl Deploy Plugin+1

·

CVE-2021-21665

·

Published

2021-06-10

·

Updated

2023-12-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins XebiaLabs XL Deploy Plugin versions 10.0.1 and earlier
Description A cross-site request forgery (CSRF) vulnerability allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
Recommendations For Jenkins XebiaLabs XL Deploy Plugin versions 10.0.1 and earlier, update to version 10.0.2 or later, which requires POST requests and Overall/Administer permission for the affected form validation method. As a temporary workaround, consider restricting access to the plugin's form validation method to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21665
GHSA-38PM-74XC-PHCW

Affected Products

Jenkins
Jenkins Xebialabs Xl Deploy Plugin