CVE Published: 31/08/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Code Coverage API Plugin Status : PUBLISHED
CVE-2021-21677 Description
Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution vulnerability.