First published: Fri Nov 12 2021(Updated: )
Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Performance | <=3.20 | |
maven/org.jenkins-ci.plugins:performance | <=3.20 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21701 is a vulnerability in Jenkins Performance that allows remote attackers to disclose sensitive information.
The vulnerability exists within the TaurusParser class in Jenkins Performance, allowing improper XXE processing.
Yes, authentication is required to exploit this vulnerability.
CVE-2021-21701 has a severity rating of 6.5 (medium).
To fix CVE-2021-21701, update Jenkins Performance to version 3.21 or later.