CVE-2021-21649

Severity
5.4MEDIUM
EPSS
0.2%
top 59.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateJun 16

Description

Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Cross-site Scripting in Jenkins Dashboard View Plugin2021-06-16
GHSA
Cross-site Scripting in Jenkins Dashboard View Plugin2021-06-16
CVEList
CVE-2021-21649: Jenkins Dashboard View Plugin 22021-05-11

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2021-05-112021-05-11
CVE-2021-21649 (MEDIUM CVSS 5.4) | Jenkins Dashboard View Plugin 2.15 | cvebase.io