CVE-2021-21603Cross-site Scripting in Project Jenkins

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 45.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 24

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDjenkins/jenkins2.263.1+1
CVEListV5jenkins_project/jenkinsunspecified2.274+1

🔴Vulnerability Details

3
OSV
XSS vulnerability in Jenkins notification bar2022-05-24
GHSA
XSS vulnerability in Jenkins notification bar2022-05-24
CVEList
CVE-2021-21603: Jenkins 22021-01-13

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2021-01-132021-01-13
Red Hat
jenkins: XSS vulnerability in notification bar2021-01-13
CVE-2021-21603 — Cross-site Scripting | cvebase