First published: Fri Jun 18 2021(Updated: )
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Generic Webhook Trigger | <=1.72 | |
maven/org.jenkins-ci.plugins:generic-webhook-trigger | <=1.72 | 1.74 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21669 is a vulnerability in the Jenkins Generic Webhook Trigger Plugin 1.72 and earlier that allows XML external entity (XXE) attacks.
CVE-2021-21669 has a severity rating of 9.8 (Critical).
CVE-2021-21669 affects Jenkins instances running the Generic Webhook Trigger Plugin version 1.72 and earlier, allowing attackers to perform XML external entity (XXE) attacks.
The affected versions of the Generic Webhook Trigger Plugin are 1.72 and earlier.
To fix CVE-2021-21669, upgrade the Generic Webhook Trigger Plugin to version 1.74 or later.