#VU49526 XML injection in Jenkins and Jenkins LTS - CVE-2021-21604

 

#VU49526 XML injection in Jenkins and Jenkins LTS - CVE-2021-21604

Published: January 13, 2021 / Updated: January 14, 2021


Vulnerability identifier: #VU49526
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-21604
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Jenkins
Jenkins LTS
Software vendor:
Jenkins

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper handling of REST API XML deserialization errors. A remote authenticated attacker can pass specially crafted XML data to the application and perform arbitrary actions on the system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links