Vulnerability record · CVE-2021-21616 · published 24 February 2021
CVE-2021-21616: Jenkins Active Choices Plugin stored XSS via reference parameter values
Jenkins · Active Choices
The Jenkins Active Choices Plugin through 2.5.2 does not escape reference parameter values, allowing stored cross-site scripting. An attacker with Job/Configure permission can persist script that executes in the browser of other users viewing the affected job.
Description
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Automated analysis
medium priorityRequires authenticated Job/Configure permission and user interaction, and CVSS rates it medium, though the high EPSS score warrants attention.
What it is
The Jenkins Active Choices Plugin through 2.5.2 does not escape reference parameter values, allowing stored cross-site scripting. An attacker with Job/Configure permission can persist script that executes in the browser of other users viewing the affected job.
Impact
An attacker can run arbitrary script in the context of a victim's Jenkins session, potentially stealing session data or performing actions as that user. The CVSS vector limits impact to low confidentiality and integrity with no availability effect.
Attack surface
Reached over the network through the Jenkins web UI; the attacker needs Job/Configure permission and the victim must view the affected job, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, though EPSS is high at 0.788 (99.6th percentile). No ransomware usage is documented.
What to do
- Upgrade the Active Choices Plugin to a version later than 2.5.2 per the Jenkins advisory.
- Restrict Job/Configure permission to trusted users only.
- Review existing job configurations for injected reference parameter values and remove any suspicious content.
- Apply a restrictive Content-Security-Policy on the Jenkins UI where feasible.
Detection
- Search Jenkins job configuration history and config.xml files for script tags or event handlers in reference parameter values.
- Monitor Jenkins audit logs for Job/Configure permission changes or unusual configuration edits.
- Inspect web access logs for requests containing encoded script payloads in job parameter fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/02/24/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2192 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/02/24/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2192 | Vendor Advisory |
Track CVE-2021-21616 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21616), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.