Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4577 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types. |
Github GHSA |
GHSA-mj7q-cmf3-mg7h | Stored XSS vulnerability in Jenkins on new item page |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.652Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21611
No data.
Status : Modified
Published: 2021-01-13T16:15:14.087
Modified: 2024-11-21T05:48:41.780
Link: CVE-2021-21611
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA