CVE-2021-21649
published 2021-05-11CVE-2021-21649: Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS)…
medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials_plugin | — | — |
| jenkins | dashboard_view | <= 2.15 | — |
| jenkins | dashboard_view_plugin | — | — |
| jenkins | ids_in_xray_test_management_for_jira_plugin | — | — |
| jenkins | p4_plugin | — | — |
| jenkins | s3_publisher_plugin | — | — |
| jenkins | xcode_integration_plugin | — | — |
| jenkins | xray_test_management_for_jira_plugin | — | — |
| jenkins_project | jenkins_dashboard_view_plugin | unspecified – 2.15 | — |