PT-2022-18291 · Jenkins · Jenkins Extended Choice Parameter Plugin+1

Oleg Nenashev

·

Published

2022-03-15

·

Updated

2023-11-30

·

CVE-2022-27204

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins Extended Choice Parameter Plugin versions 346.vd87693c5a 86c and earlier
Description A cross-site request forgery vulnerability allows attackers to connect to an attacker-specified URL. The issue arises because the plugin does not perform a permission check on form validation methods, allowing attackers with Overall/Read permission to exploit this. Furthermore, these form validation methods do not require POST requests, resulting in the vulnerability.
Recommendations For versions 346.vd87693c5a 86c and earlier, consider disabling the form validation methods until a patch is available to prevent exploitation. Restrict access to the plugin to minimize the risk of exploitation, especially for users with Overall/Read permission. Avoid using the plugin for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27204
GHSA-FQPX-XFJR-2QR9

Affected Products

Jenkins
Jenkins Extended Choice Parameter Plugin