PT-2021-14665 · Jenkins · Jenkins Artifact Repository Parameter Plugin+1

S0Nnguy3N

·

Published

2021-02-24

·

Updated

2023-11-03

·

CVE-2021-21622

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Artifact Repository Parameter Plugin versions 1.0.0 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability because parameter names and descriptions are not escaped. This vulnerability is exploitable by attackers with Job/Configure permission.
Recommendations For Jenkins Artifact Repository Parameter Plugin versions 1.0.0 and earlier, update to version 1.0.1 or later, which escapes parameter names and descriptions, to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-21622
GHSA-GC87-QWMV-7X9X

Affected Products

Jenkins
Jenkins Artifact Repository Parameter Plugin