PT-2021-14711 · Jenkins · Jenkins Scriptler Plugin+1

Published

2021-06-16

·

Updated

2023-11-03

·

CVE-2021-21668

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Scriptler Plugin versions 3.1 and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability because the script content is not escaped. This vulnerability is exploitable by attackers with Scriptler/Configure permission.
Recommendations For Jenkins Scriptler Plugin versions 3.1 and earlier, update to version 3.2 or later, which escapes script content and resolves the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-21668
GHSA-5C6C-W4C4-VGVX

Affected Products

Jenkins
Jenkins Scriptler Plugin