Lucene search

K
osvGoogleOSV:CVE-2021-21610
HistoryJan 13, 2021 - 4:15 p.m.

CVE-2021-21610

2021-01-1316:15:14
Google
osv.dev
7

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.8%

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.8%