CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects Jenkins.
CVE
CVE-2021-21646
Severity
HIGH
CVSS
8.8
EPSS
1.75%
Jenkins
Original NVD Description
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
Related CVEs
Other vulnerabilities affecting the same vendor(s)