#VU49526 XML injection in Jenkins and Jenkins LTS - CVE-2021-21604
Published: January 13, 2021 / Updated: January 14, 2021
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of REST API XML deserialization errors. A remote authenticated attacker can pass specially crafted XML data to the application and perform arbitrary actions on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.