PT-2021-14678 · Jenkins · Jenkins Rest List Parameter Plugin+1

Kevin Guerroudj

·

Published

2021-03-30

·

Updated

2023-11-03

·

CVE-2021-21635

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins REST List Parameter Plugin versions 1.3.0 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability due to the failure to escape a parameter name reference in embedded JavaScript. This vulnerability is exploitable by attackers with Job/Configure permission.
Recommendations For Jenkins REST List Parameter Plugin versions 1.3.0 and earlier, update to version 1.3.1 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-21635
GHSA-X3M6-VCP7-98MR

Affected Products

Jenkins
Jenkins Rest List Parameter Plugin