Vulnerability record · CVE-2021-21699 · published 12 November 2021
CVE-2021-21699: Jenkins Active Choices Plugin stored XSS via unescaped parameter name
Jenkins · Active Choices
The Jenkins Active Choices Plugin 2.5.6 and earlier fails to escape the parameter name of reactive parameters and dynamic reference parameters. This allows a stored cross-site scripting payload to be persisted and rendered to other users. Because the plugin is widely used in Jenkins job configuration, the flaw matters for any instance where multiple users can configure jobs.
Description
Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityExploitation requires authenticated Job/Configure permission and victim interaction, which limits reach, though the high EPSS score and stored nature warrant prompt patching.
What it is
The Jenkins Active Choices Plugin 2.5.6 and earlier fails to escape the parameter name of reactive parameters and dynamic reference parameters. This allows a stored cross-site scripting payload to be persisted and rendered to other users. Because the plugin is widely used in Jenkins job configuration, the flaw matters for any instance where multiple users can configure jobs.
Impact
An attacker with Job/Configure permission can store script that executes in the browser of another Jenkins user viewing the affected job, enabling session theft or actions in that user's context. The scope change in the CVSS vector reflects that the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through the Jenkins web UI by a user who holds Job/Configure permission; the victim must view the affected job configuration or page, so user interaction is required. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged in the record, but EPSS is very high at 0.885 (99.8th percentile), indicating elevated predicted exploitation activity. The vendor advisory confirms the issue and the fix.
What to do
- Upgrade the Jenkins Active Choices Plugin to a version later than 2.5.6 that contains the SECURITY-2219 fix.
- Restrict Job/Configure permission to trusted users only, since exploitation requires that permission.
- Review and remove any untrusted or unnecessary job configurations that use reactive or dynamic reference parameters.
- Apply Jenkins hardening guidance and keep the core and all plugins current to reduce exposure to related XSS issues.
Detection
- Search Jenkins job configuration XML for reactive or dynamic reference parameter definitions containing HTML or script-like characters in parameter names.
- Monitor Jenkins audit logs for Job/Configure changes made by unexpected or low-trust accounts.
- Inspect HTTP responses and browser-side alerts for injected script in parameter name fields on job configuration pages.
- Correlate Jenkins access logs for configuration views with subsequent suspicious session or API activity from the same user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/11/12/1 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2219 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/11/12/1 | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2219 | Vendor Advisory |
Track CVE-2021-21699 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21699), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.