Vulnerability record · CVE-2021-21668 · published 16 June 2021
CVE-2021-21668: Jenkins Scriptler Plugin stored XSS via unescaped script content
Jenkins · Scriptler
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, creating a stored cross-site scripting flaw. An attacker with Scriptler/Configure permission can persist malicious script content that executes in the browser of other users who view it.
Description
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires authenticated Scriptler/Configure permission and victim interaction, limiting reach, but the high EPSS score and stored nature warrant timely patching.
What it is
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, creating a stored cross-site scripting flaw. An attacker with Scriptler/Configure permission can persist malicious script content that executes in the browser of other users who view it.
Impact
An attacker can run arbitrary script in the context of a victim's Jenkins session, potentially stealing session data or performing actions as the victim. The scope change in the CVSS vector reflects impact beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins web interface; the attacker needs Scriptler/Configure permission, and a victim must view the affected content, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged, though EPSS is high at 0.76 (99.5th percentile), indicating elevated predicted likelihood.
What to do
- Upgrade the Scriptler Plugin to a version later than 3.1 that escapes script content.
- Restrict Scriptler/Configure permission to the smallest possible set of trusted administrators.
- Review existing Scriptler scripts for injected or unexpected content and remove anything suspicious.
- Apply output encoding or content security controls in Jenkins where feasible.
Detection
- Audit Jenkins logs and Scriptler configuration changes for unexpected script edits by non-admin accounts.
- Search stored Scriptler script content for HTML or JavaScript patterns that should not appear in script definitions.
- Monitor for anomalous browser-side activity or session use by accounts that viewed Scriptler pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/06/16/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-06-16/#SECURITY-2390 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/06/16/3 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-06-16/#SECURITY-2390 | Vendor Advisory |
Track CVE-2021-21668 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21668), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.