CVE-2021-21603 log

Source
Severity High
Remote Yes
Type Cross-site scripting
Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents (typically shown after form submissions via Apply button). This results in a cross-site scripting (XSS) vulnerability exploitable by attackers able to influence notification bar contents. Jenkins 2.275, LTS 2.263.2 escapes the content shown in notification bars.
Group Package Affected Fixed Severity Status Ticket
AVG-1446 jenkins 2.274-1 2.275-1 High Fixed
Date Advisory Group Package Severity Type
20 Jan 2021 ASA-202101-41 AVG-1446 jenkins High multiple issues
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-1889
https://github.com/jenkinsci/jenkins/commit/f5d98421604e44f398e7de9d222b191a705608af