CVE-2021-21658: XEE
Published May 25, 2021
·Updated
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:nuget<1.1
1.1
Jenkins Nuget Jenkins<=1.0
Event History
May 25, 2021
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
Description
May 24, 2022
Advisory Published
07:03 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-21658?
CVE-2021-21658 is classified as a medium severity vulnerability due to the potential for XML external entity (XXE) attacks.
2
How do I fix CVE-2021-21658?
To fix CVE-2021-21658, upgrade the Jenkins Nuget Plugin to version 1.1 or later.
3
What software is affected by CVE-2021-21658?
CVE-2021-21658 affects Jenkins Nuget Plugin version 1.0 and earlier.
4
What type of vulnerability is CVE-2021-21658?
CVE-2021-21658 is an XML External Entity (XXE) vulnerability.
5
What feature is impacted by CVE-2021-21658?
The vulnerability CVE-2021-21658 impacts the 'Build on NuGet updates' feature of the Jenkins Nuget Plugin.