CVE-2021-21611 log

Source
Severity High
Remote Yes
Type Cross-site scripting
Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page. This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types. Jenkins 2.275, LTS 2.263.2 escapes display names and IDs of item types shown on the New Item page.
Group Package Affected Fixed Severity Status Ticket
AVG-1446 jenkins 2.274-1 2.275-1 High Fixed
Date Advisory Group Package Severity Type
20 Jan 2021 ASA-202101-41 AVG-1446 jenkins High multiple issues
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2171
https://github.com/jenkinsci/jenkins/commit/8c451b08886561a914ef0c30cbb9d40ea33a9bbe