PT-2021-14723 · Jenkins · Jenkins Nested View Plugin+1

Brian Hysell

·

Published

2021-08-31

·

Updated

2023-11-22

·

CVE-2021-21680

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Nested View Plugin versions 1.20 and earlier
Description The issue arises from the Jenkins Nested View Plugin not configuring its XML transformer to prevent XML external entity (XXE) attacks. This allows attackers who can configure views to have Jenkins parse a crafted view XML definition, using external entities for extraction of secrets from the Jenkins controller or for server-side request forgery.
Recommendations For Jenkins Nested View Plugin versions 1.20 and earlier, update to version 1.21 or later, which disables external entity resolution for its XML transformer.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2021-21680
GHSA-5WC4-W63V-97C3

Affected Products

Jenkins
Jenkins Nested View Plugin