Aller au contenu

Fiche vulnérabilité

CVE-2021-21604 : faille élevée jenkins jenkins (CVSS 8.0)

Description

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.

En bref

Sévérité
Élevée (CVSS 8.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 janv. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • jenkins jenkins

Références

Rechercher une autre vulnérabilité dans la base CVE