CVE-2021-21678
Java vulnerability analysis and mitigation

Overview

CVE-2021-21678 is a high-severity vulnerability affecting the Jenkins SAML Plugin versions 2.0.7 and earlier. The vulnerability was discovered in August 2021 and involves a security flaw in the CSRF protection mechanism. The issue was originally introduced in SAML Plugin version 1.1.3 (Jenkins Advisory).

Technical details

The vulnerability stems from an extension point in Jenkins that allows selective disabling of cross-site request forgery (CSRF) protection for specific URLs. The SAML Plugin implements this extension point for the URL that users are redirected to after login. In affected versions, this implementation was too permissive, allowing attackers to craft URLs that would bypass the CSRF protection of any target URL. The vulnerability has been assigned a High severity CVSS rating (Jenkins Advisory, OSS Security).

Impact

The vulnerability allows attackers to bypass CSRF protection mechanisms for any target URL within Jenkins. This could potentially lead to unauthorized actions being performed on behalf of authenticated users (Jenkins Advisory).

Mitigation and workarounds

The vulnerability has been fixed in SAML Plugin version 2.0.8, which restricts which URLs can have CSRF protection disabled to only the specific URL that requires it. Users are strongly advised to update to this version to protect against potential attacks (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55749HIGH8.7
  • JavaJava
  • org.xwiki.platform:xwiki-platform-tool-jetty-resources
NoYesDec 01, 2025
CVE-2025-64775HIGH7.5
  • JavaJava
  • javapackages-tools:201801::guice-servlet
NoYesDec 01, 2025
CVE-2025-13806MEDIUM6.9
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-66453MEDIUM5.5
  • JavaJava
  • org.mozilla:rhino
NoYesDec 03, 2025
CVE-2025-13472MEDIUM5.3
  • JavaJava
  • com.blazemeter.plugins:blazemeterjenkinsplugin
NoYesDec 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management