cbcvebase.
CVE-2021-21699
published 2021-11-12

CVE-2021-21699: Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

Affected

10 ranges
VendorProductVersion rangeFixed in
ipythonipython>= 0 < 5.115.11
ipythonipython>= 6.0.0 < 7.16.37.16.3
ipythonipython>= 7.17.0 < 7.31.17.31.1
ipythonipython>= 8.0.0 < 8.0.18.0.1
jenkinsactive_choices<= 2.5.6
jenkinsactive_choices_plugin
jenkinsowasp_dependency-check_plugin
jenkinsperformance_plugin
jenkinsscriptler_plugin
jenkins_projectjenkins_active_choices_pluginunspecified – 2.5.6