Vulnerability record · CVE-2021-21618 · published 24 February 2021
CVE-2021-21618: Jenkins Repository Connector Plugin stored XSS via unescaped parameter names
Jenkins · Repository Connector
Jenkins Repository Connector Plugin 2.0.2 and earlier fails to escape parameter names and descriptions for past builds, creating a stored cross-site scripting flaw. An attacker with Item/Configure permission can inject script that executes in the browser of other users viewing the affected build data.
Description
Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires authenticated Item/Configure permission and victim interaction, but the stored XSS can affect other users and EPSS is very high.
What it is
Jenkins Repository Connector Plugin 2.0.2 and earlier fails to escape parameter names and descriptions for past builds, creating a stored cross-site scripting flaw. An attacker with Item/Configure permission can inject script that executes in the browser of other users viewing the affected build data.
Impact
An attacker can run arbitrary JavaScript in a victim's Jenkins session, potentially stealing session data or performing actions as the victim. The scope change in the CVSS vector means the script can affect resources beyond the vulnerable component.
Attack surface
Reachable over the network through the Jenkins web interface. The attacker needs Item/Configure permission, and a victim must view the affected past build page, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided. EPSS is high at 0.81765 (99.6th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade Jenkins Repository Connector Plugin to a version later than 2.0.2 as directed by the vendor advisory.
- Restrict Item/Configure permission to trusted users only.
- Review and remove any untrusted parameter names or descriptions in past build records.
- Apply Jenkins security hardening guidance for plugin and permission management.
Detection
- Search Jenkins build parameter names and descriptions for HTML or script tags.
- Monitor Jenkins audit logs for unexpected Item/Configure permission changes or suspicious configuration edits.
- Inspect web access logs for requests containing encoded script payloads in build parameter fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2183 | Vendor Advisory |
| https://www.jenkins.io/security/advisory/2021-02-24/#SECURITY-2183 | Vendor Advisory |
Track CVE-2021-21618 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21618), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.