Session Fixation in Jenkins and Jenkins LTS - CVE-2021-21671

 

Session Fixation in Jenkins and Jenkins LTS - CVE-2021-21671

Published: July 1, 2021


Vulnerability identifier: #VU54492
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21671
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product does not invalidate the existing session on login. A remote attacker can use social engineering techniques to gain administrator access to Jenkins.


Affected software

Jenkins
Jenkins LTS
Arch Linux
butane (Red Hat package)
cri-o (Red Hat package)
jenkins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
ovn2.13 (Red Hat package)
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Container Platform

How to mitigate CVE-2021-21671

Install updates from vendor's website.

Jenkins - update to 2.300
Jenkins LTS - update to 2.289.2
butane (Red Hat package) - update to 0.12.1-2.rhaos4.8.el8
cri-o (Red Hat package) - addressed in versions 1.19.3-11.rhaos4.6.git66a69b8.el7, 1.19.3-11.rhaos4.6.git66a69b8.el8, 1.20.4-8.rhaos4.7.git74c6592.el7, 1.20.4-8.rhaos4.7.git74c6592.el8, 1.21.3-6.rhaos4.8.gite34bf50.el7, 1.21.3-6.rhaos4.8.gite34bf50.el8
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.3
jenkins (Red Hat package) - addressed in versions 2.289.2.1628252553-1.el8, 2.289.2.1629437819-1.el8, 2.289.3.1633554819-1.el8
Red Hat OpenShift Container Platform - addressed in versions 4.6.44, 4.7.24, 4.8.15
openshift-ansible (Red Hat package) - addressed in versions 4.6.0-202108202025.p0.git.4ec6967.assembly.stream.el7, 4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202108202025.p0.git.2b525e8.assembly.stream.el7, 4.6.0-202108202025.p0.git.2b525e8.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.6.0-202108202025.p0.git.0063daa.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.6.0-202108202025.p0.git.4c3480d.assembly.stream.el7, 4.6.0-202108202025.p0.git.4c3480d.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.6.0-202108202025.p0.git.39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.6.1629443573-1.el8, 4.8.1633555500-1.el8
ovn2.13 (Red Hat package) - update to 20.12.0-140.el8fdp

External References

Related Security Bulletins