Vulnerabilities > CVE-2021-21673 - Unspecified vulnerability in Jenkins CAS
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 |