PT-2021-14671 · Jenkins · Jenkins Build With Parameters Plugin+1

Kevin Guerroudj

·

Published

2021-03-30

·

Updated

2023-11-03

·

CVE-2021-21628

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Build With Parameters Plugin versions 1.5 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability because parameter names and descriptions are not properly escaped. This can be exploited by attackers with Job/Configure permission.
Recommendations For Jenkins Build With Parameters Plugin versions 1.5 and earlier, update to version 1.5.1 or later, which properly escapes parameter names and descriptions to prevent the stored cross-site scripting (XSS) vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-21628
GHSA-XJRG-6FV9-6RJG

Affected Products

Jenkins
Jenkins Build With Parameters Plugin