
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-21622 is a stored cross-site scripting (XSS) vulnerability discovered in Jenkins Artifact Repository Parameter Plugin versions 1.0.0 and earlier. The vulnerability was disclosed on February 24, 2021, affecting the parameter names and descriptions functionality of the plugin. The issue impacts Jenkins installations using the affected plugin versions (Jenkins Advisory).
The vulnerability stems from the plugin's failure to properly escape parameter names and descriptions, leading to a stored cross-site scripting vulnerability. The severity is rated as High according to the CVSS scoring system. The vulnerability is exploitable by attackers who have Job/Configure permission in the Jenkins environment (Jenkins Advisory).
When successfully exploited, this vulnerability allows attackers with Job/Configure permission to execute arbitrary JavaScript code in the context of other users' browsers who view the affected Jenkins pages. This could potentially lead to session hijacking, credential theft, or other malicious actions performed in the context of the victim's browser session (Jenkins Advisory).
The vulnerability requires an attacker to have Job/Configure permission in the Jenkins environment to exploit. This means the attacker must have legitimate access to configure jobs in the Jenkins instance before they can inject malicious scripts through parameter names and descriptions (Jenkins Advisory).
The vulnerability has been fixed in Artifact Repository Parameter Plugin version 1.0.1, which properly escapes parameter names and descriptions. Users are strongly advised to upgrade to this version to mitigate the vulnerability. No alternative workarounds have been provided (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."