CVE-2021-21610
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
13/01/2021
Last modified:
02/11/2023
Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | 2.263.1 (including) | |
| cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* | 2.274 (including) |
To consult the complete list of CPE names with products and versions, see this page



