CVE-2021-21611 – Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs o …

Vuln ID: CVE-2021-21611

Published:  2021-01-13  16:15:14Z

Description: Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.

Source: NVD.NIST.GOV