AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-43578

HIGH · CVSS 8.1 EPSS 1.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-43578
Severity
HIGH
CVSS
8.1
EPSS
1.07%
Jenkins

Original NVD Description

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON string.