Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
https://github.com/advisories/GHSA-x77r-7m5w-pqq2
https://www.jenkins.io/security/advisory/2021-08-31/#SECURITY-2470