{"id":"CVE-2021-21641","details":"A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.","aliases":["GHSA-5cxw-8v65-76vf"],"modified":"2026-07-09T00:22:31.371857Z","published":"2021-04-07T14:15:17.093Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/04/07/2"},{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2021-04-07/#SECURITY-2293"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/promoted-builds-plugin","events":[{"introduced":"0"},{"last_affected":"5b741e2a66e1863360e599763dd4a868ba8d96d8"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:jenkins:promoted_builds:*:*:*:*:*:jenkins:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.9"}]}}],"versions":["untagged-0514034a2dbca289d2ca","promoted-builds-3.9","promoted-builds-3.7","promoted-builds-3.6","promoted-builds-3.5","promoted-builds-3.4","promoted-builds-3.3","promoted-builds-3.2","promoted-builds-3.1","promoted-builds-3.0","promoted-builds-2.31.1","promoted-builds-2.31","promoted-builds-2.30","promoted-builds-2.29.1","promoted-builds-2.29","promoted-builds-2.28.1","promoted-builds-2.28","promoted-builds-2.27","promoted-builds-2.26","promoted-builds-2.25","promoted-builds-2.24.1","promoted-builds-2.24","promoted-builds-2.23.1","promoted-builds-2.23","promoted-builds-2.21","promoted-builds-2.20","promoted-builds-2.19","promoted-builds-2.18","promoted-builds-2.17","promoted-builds-2.16","promoted-builds-2.15","promoted-builds-2.14","promoted-builds-2.13","promoted-builds-2.12","promoted-builds-2.11","promoted-builds-2.10","promoted-builds-2.9","promoted-builds-2.8","promoted-builds-2.7","promoted-builds-2.6.2","promoted-builds-2.6.1","promoted-builds-2.6","promoted-builds-2.5","promoted-builds-2.4","promoted-builds-2.3.1","promoted-builds-2.3","promoted-builds-2.2","promoted-builds-2.1","promoted-builds-2.0","promoted-builds-1.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21641.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}