CVE-2021-21616: XSS
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Other sources
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Jenkins Active Choices Plugin 2.5.3 escapes reference parameter values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21616?
CVE-2021-21616 is considered a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2021-21616?
To fix CVE-2021-21616, upgrade the Jenkins Active Choices Plugin to version 2.5.3 or later.
Who is affected by CVE-2021-21616?
CVE-2021-21616 affects users of Jenkins Active Choices Plugin versions 2.5.2 and earlier.
What is the impact of exploiting CVE-2021-21616?
Exploiting CVE-2021-21616 allows attackers with Job/Configure permission to execute arbitrary JavaScript in users' browsers.
Is CVE-2021-21616 related to any other vulnerabilities?
CVE-2021-21616 is related to other XSS vulnerabilities within the Jenkins ecosystem, particularly those involving insufficient input validation.