CVE-2021-21646
HIGH8.8EPSS 0.39%Remote code execution vulnerability in Jenkins Templating Engine Plugin
Published: 5/24/2022Modified: 2/16/2024
Description
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin. This vulnerability allows attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. Jenkins Templating Engine Plugin 2.2 integrates with Script Security Plugin to protect its pipeline configurations.
Affected packages (1)
- Maven/org.jenkins-ci.plugins:templating-enginefrom 0, < 2.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-21646
- PATCHhttps://github.com/jenkinsci/templating-engine-plugin
- WEBhttps://github.com/jenkinsci/templating-engine-plugin/commit/aed14bed7333329f51330d0a8111e4d94cdee3e6
- WEBhttps://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2311
- WEBhttp://www.openwall.com/lists/oss-security/2021/04/21/2