CVE-2021-21659

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-21659
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21659.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-21659
Aliases
Published
2021-05-25T17:15:08Z
Modified
2025-01-14T08:52:26.731361Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

References

Affected packages

Git / github.com/jenkinsci/urltrigger-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/urltrigger-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

urltrigger-0.*

urltrigger-0.1
urltrigger-0.10
urltrigger-0.11
urltrigger-0.12
urltrigger-0.13
urltrigger-0.14
urltrigger-0.15
urltrigger-0.16
urltrigger-0.17
urltrigger-0.18
urltrigger-0.19
urltrigger-0.2
urltrigger-0.20
urltrigger-0.21
urltrigger-0.22
urltrigger-0.23
urltrigger-0.24
urltrigger-0.25
urltrigger-0.26
urltrigger-0.27
urltrigger-0.28
urltrigger-0.29
urltrigger-0.3
urltrigger-0.30
urltrigger-0.31
urltrigger-0.32
urltrigger-0.33
urltrigger-0.34
urltrigger-0.35
urltrigger-0.36
urltrigger-0.37
urltrigger-0.38
urltrigger-0.39
urltrigger-0.4
urltrigger-0.4.1
urltrigger-0.4.2
urltrigger-0.4.3
urltrigger-0.40
urltrigger-0.41
urltrigger-0.43
urltrigger-0.44
urltrigger-0.45
urltrigger-0.46
urltrigger-0.47
urltrigger-0.48
urltrigger-0.5
urltrigger-0.5.1
urltrigger-0.6
urltrigger-0.7
urltrigger-0.8
urltrigger-0.9