CVE-2021-21648: XSS
Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides. This results in a reflected cross-site scripting (XSS) vulnerability. Credentials Plugin 2.3.19 restricts the user-controlled information it provides to a safe subset.
References:
https://www.jenkins.io/security/advisory/2021-05-11/
Other sources
Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.
Jenkins Credentials Plugin prior to 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.
Jenkins Credentials Plugin 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 restricts the user-controlled information it provides to a safe subset.
The reflected cross-site scripting (XSS) vulnerability was found in jenkins credentials plugin. On a view it there is no escape from provided by user information (user-controlled).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21648?
CVE-2021-21648 is a vulnerability in Jenkins Credentials Plugin that allows for a reflected cross-site scripting (XSS) attack.
How severe is CVE-2021-21648?
CVE-2021-21648 has a severity rating of 8.8 (high).
Which versions of Jenkins Credentials Plugin are affected?
Jenkins Credentials Plugin versions 2.3.18 and earlier are affected.
How can I fix CVE-2021-21648?
To fix CVE-2021-21648, upgrade your Jenkins Credentials Plugin to version 2.3.19 or later.
Where can I find more information about CVE-2021-21648?
You can find more information about CVE-2021-21648 at the following links: [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2021-05-11/), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:2437).