Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5032 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator. |
Github GHSA |
GHSA-qv6f-rcv6-6q3x | Improper handling of REST API XML deserialization errors in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.595Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21604
No data.
Status : Modified
Published: 2021-01-13T16:15:13.523
Modified: 2024-11-21T05:48:41.053
Link: CVE-2021-21604
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA