Jenkins Extended Choice Parameter vulnerabilities
5 known vulnerabilities affecting jenkins/extended_choice_parameter.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2022-29038MEDIUMCVSS 5.4≤ 346.vd87693c5a_86c2022-04-12
CVE-2022-29038 [MEDIUM] CWE-79 CVE-2022-29038: Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2022-27204HIGHCVSS 8.8≤ 346.vd87693c5a_86c2022-03-15
CVE-2022-27204 [HIGH] CWE-352 CVE-2022-27204: A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5
A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL.
nvd
CVE-2022-27205MEDIUMCVSS 4.3≤ 346.vd87693c5a_86c2022-03-15
CVE-2022-27205 [MEDIUM] CWE-862 CVE-2022-27205: A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlie
A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
nvd
CVE-2022-27202MEDIUMCVSS 5.4≤ 346.vd87693c5a_86c2022-03-15
CVE-2022-27202 [MEDIUM] CWE-79 CVE-2022-27202: Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value an
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2022-27203MEDIUMCVSS 6.5≤ 346.vd87693c5a_86c2022-03-15
CVE-2022-27203 [MEDIUM] CWE-22 CVE-2022-27203: Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/C
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller.
nvd