Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4577 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types. |
Github GHSA |
GHSA-mj7q-cmf3-mg7h | Stored XSS vulnerability in Jenkins on new item page |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.652Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21611
No data.
Status : Modified
Published: 2021-01-13T16:15:14.087
Modified: 2024-11-21T05:48:41.780
Link: CVE-2021-21611
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA