cbcvebase.
CVE-2021-21669
published 2021-06-18

CVE-2021-21669: Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Affected

3 ranges
VendorProductVersion rangeFixed in
jenkinsgeneric_webhook_trigger<= 1.72
jenkinsgeneric_webhook_trigger_plugin
jenkins_projectjenkins_generic_webhook_trigger_pluginunspecified – 1.72