Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
{ "versions": [ { "introduced": "2.266" }, { "fixed": "2.300" }, { "introduced": "2.277.1" }, { "fixed": "2.289.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21671.json"