PT-2021-14692 · Jenkins · Jenkins Dashboard View Plugin+1
Kevin Guerroudj
·
Published
2021-05-11
·
Updated
2023-11-03
·
CVE-2021-21649
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Dashboard View Plugin versions 2.15 and earlier
Jenkins Dashboard View Plugin versions prior to 2.16
Jenkins Dashboard View Plugin version 2.12.1 and earlier
Description
The issue is related to a stored cross-site scripting (XSS) vulnerability. It occurs because URLs referenced in Image Dashboard Portlets are not properly escaped. This vulnerability can be exploited by attackers who have View/Configure permission. The estimated number of potentially affected devices worldwide is not available.
Recommendations
For Jenkins Dashboard View Plugin versions 2.15 and earlier, update to version 2.16 or later.
For Jenkins Dashboard View Plugin versions prior to 2.16, update to version 2.16 or later.
For Jenkins Dashboard View Plugin version 2.12.1 and earlier, update to version 2.12.1 or later, or apply the configuration change to use the new
imageUrl property instead of url for image URLs.
As a temporary workaround, consider restricting access to the Image Dashboard Portlets to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Dashboard View Plugin