CVE-2021-21677

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
31/08/2021
Last modified:
22/11/2023

Description

Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:code_coverage_api:*:*:*:*:*:jenkins:*:* 1.4.0 (including)