Vulnerability record · CVE-2021-21667 · published 16 June 2021
CVE-2021-21667: Jenkins Scriptler Plugin stored XSS via unescaped parameter names
Jenkins · Scriptler
Jenkins Scriptler Plugin 3.2 and earlier fails to escape parameter names rendered in job configuration forms, creating a stored cross-site scripting flaw. Because the payload persists in job configuration, it can fire for other users who view or edit those forms, not just the person who injected it.
Description
Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityStored XSS with scope change but gated behind Scriptler/Configure permission and victim interaction, and no KEV listing, keeps real-world risk moderate despite a high EPSS score.
What it is
Jenkins Scriptler Plugin 3.2 and earlier fails to escape parameter names rendered in job configuration forms, creating a stored cross-site scripting flaw. Because the payload persists in job configuration, it can fire for other users who view or edit those forms, not just the person who injected it.
Impact
An attacker with Scriptler/Configure permission can store script that executes in the browser of other Jenkins users viewing the affected configuration forms, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) reflects impact beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins job configuration UI; the attacker needs Scriptler/Configure permission, and a victim must view the affected form, so user interaction is required (CVSS PR:L/UI:R).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, though EPSS is high at 0.757 (99.5th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade the Scriptler Plugin past version 3.2 to the fixed release named in the Jenkins advisory of 2021-06-16.
- If upgrade is not immediately possible, restrict Scriptler/Configure permission to a minimal set of trusted administrators.
- Review and remove any Scriptler parameter names containing HTML or script content from existing job configurations.
- Apply Jenkins hardening such as Content-Security-Policy headers to reduce XSS impact.
Detection
- Search Jenkins job configuration XML for Scriptler parameter names containing angle brackets, script tags or event handler attributes.
- Monitor Jenkins audit logs for Scriptler/Configure permission grants or configuration changes by unexpected accounts.
- Review HTTP access logs for requests to Scriptler configuration endpoints from unusual source addresses or sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/06/16/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-06-16/#SECURITY-2224 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/06/16/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-06-16/#SECURITY-2224 | Vendor Advisory |
Track CVE-2021-21667 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21667), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.