Vulnerability record · CVE-2021-21628 · published 30 March 2021
CVE-2021-21628: Jenkins Build With Parameters Plugin stored XSS via unescaped parameter names
Jenkins · Build With Parameters
The Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, allowing stored cross-site scripting. An attacker with Job/Configure permission can plant script that executes in the browser of other users who view the affected job, which matters because Jenkins is a high-value target for credential and pipeline abuse.
Description
Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires authenticated Job/Configure permission and victim interaction, but the stored XSS can compromise other Jenkins users and EPSS is very high.
What it is
The Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, allowing stored cross-site scripting. An attacker with Job/Configure permission can plant script that executes in the browser of other users who view the affected job, which matters because Jenkins is a high-value target for credential and pipeline abuse.
Impact
An attacker gains script execution in the context of other Jenkins users viewing the job, enabling session or credential theft and actions performed as those users. The scope change in the CVSS vector reflects impact beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins web UI where parameter names and descriptions are rendered. The attacker needs Job/Configure permission, and a victim must view the affected job page, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.8143 (99.62nd percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade the Build With Parameters Plugin to a version later than 1.5 that escapes parameter names and descriptions.
- If immediate upgrade is not possible, restrict Job/Configure permission to trusted users only.
- Review Jenkins users and groups for unnecessary Job/Configure grants and remove them.
- Apply output encoding or a content security policy in Jenkins to reduce XSS impact where feasible.
Detection
- Search Jenkins job configurations for parameter names or descriptions containing script tags or HTML event handlers.
- Monitor Jenkins audit logs for Job/Configure permission changes or new job configuration edits by unexpected users.
- Inspect web access logs for requests to job pages containing suspicious encoded script payloads.
- Review browser or proxy alerts for script execution originating from Jenkins job parameter fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/03/30/1 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-03-30/#SECURITY-2231 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/03/30/1 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-03-30/#SECURITY-2231 | Vendor Advisory |
Track CVE-2021-21628 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21628), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.