CVE-2021-21619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
24/02/2021
Last modified:
02/11/2023

Description

Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:claim:*:*:*:*:*:jenkins:*:* 2.18.1 (including)