SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21619

Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security…

MEDIUM 5.4EPSS 9.39%

Does this matter?

Lower severity and a low EPSS score (9.39%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
9.39% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jenkins/claim
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.