VYPR
High severityNVD Advisory· Published Apr 21, 2021· Updated Aug 3, 2024

CVE-2021-21646

CVE-2021-21646

Description

Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:templating-engineMaven
< 2.22.2

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

1