← Vulnerability feed

Vulnerability record · CVE-2021-21699 · published 12 November 2021

CVE-2021-21699: Jenkins Active Choices Plugin stored XSS via unescaped parameter name

Jenkins · Active Choices

The Jenkins Active Choices Plugin 2.5.6 and earlier fails to escape the parameter name of reactive parameters and dynamic reference parameters. This allows a stored cross-site scripting payload to be persisted and rendered to other users. Because the plugin is widely used in Jenkins job configuration, the flaw matters for any instance where multiple users can configure jobs.

5.4 CVSS 3.1 Medium EPSS 88% · top 0.2% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityExploitation requires authenticated Job/Configure permission and victim interaction, which limits reach, though the high EPSS score and stored nature warrant prompt patching.

What it is

The Jenkins Active Choices Plugin 2.5.6 and earlier fails to escape the parameter name of reactive parameters and dynamic reference parameters. This allows a stored cross-site scripting payload to be persisted and rendered to other users. Because the plugin is widely used in Jenkins job configuration, the flaw matters for any instance where multiple users can configure jobs.

Impact

An attacker with Job/Configure permission can store script that executes in the browser of another Jenkins user viewing the affected job, enabling session theft or actions in that user's context. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.

Attack surface

Reached over the network through the Jenkins web UI by a user who holds Job/Configure permission; the victim must view the affected job configuration or page, so user interaction is required. No unauthenticated path is described.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged in the record, but EPSS is very high at 0.885 (99.8th percentile), indicating elevated predicted exploitation activity. The vendor advisory confirms the issue and the fix.

What to do

  • Upgrade the Jenkins Active Choices Plugin to a version later than 2.5.6 that contains the SECURITY-2219 fix.
  • Restrict Job/Configure permission to trusted users only, since exploitation requires that permission.
  • Review and remove any untrusted or unnecessary job configurations that use reactive or dynamic reference parameters.
  • Apply Jenkins hardening guidance and keep the core and all plugins current to reduce exposure to related XSS issues.

Detection

  • Search Jenkins job configuration XML for reactive or dynamic reference parameter definitions containing HTML or script-like characters in parameter names.
  • Monitor Jenkins audit logs for Job/Configure changes made by unexpected or low-trust accounts.
  • Inspect HTTP responses and browser-side alerts for injected script in parameter name fields on job configuration pages.
  • Correlate Jenkins access logs for configuration views with subsequent suspicious session or API activity from the same user.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.4CVE-2020-2289Jenkins active choices cross-site scripting vulnerabilityJenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scriptin…EPSS 0.91%5.4CVE-2020-2290Jenkins active choices cross-site scripting vulnerabilityJenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in…EPSS 0.90%5.4CVE-2017-1000386Jenkins active choices cross-site scripting vulnerabilityJenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Bui…EPSS 0.81%4.6CVE-2021-21616Jenkins Active Choices Plugin stored XSS via reference parameter valuesThe Jenkins Active Choices Plugin through 2.5.2 does not escape reference parameter values, allowing stored cross-site scripting. An attacker with Jo…EPSS 79%analysed6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21699), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.