PT-2021-14692 · Jenkins · Jenkins Dashboard View Plugin+1

Kevin Guerroudj

·

Published

2021-05-11

·

Updated

2023-11-03

·

CVE-2021-21649

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Dashboard View Plugin versions 2.15 and earlier Jenkins Dashboard View Plugin versions prior to 2.16 Jenkins Dashboard View Plugin version 2.12.1 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. It occurs because URLs referenced in Image Dashboard Portlets are not properly escaped. This vulnerability can be exploited by attackers who have View/Configure permission. The estimated number of potentially affected devices worldwide is not available.
Recommendations For Jenkins Dashboard View Plugin versions 2.15 and earlier, update to version 2.16 or later. For Jenkins Dashboard View Plugin versions prior to 2.16, update to version 2.16 or later. For Jenkins Dashboard View Plugin version 2.12.1 and earlier, update to version 2.12.1 or later, or apply the configuration change to use the new imageUrl property instead of url for image URLs. As a temporary workaround, consider restricting access to the Image Dashboard Portlets to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-21649
GHSA-JWHM-9CJM-4493

Affected Products

Jenkins
Jenkins Dashboard View Plugin