VulnerabilityModified
CVE-2021-21700
Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler…
MEDIUM 5.4EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/scriptler
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2021/11/12/1Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2406Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/11/12/1Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2406Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.