Unauthorized Access to JSON and Java Properties Files in Jenkins Extended Choice Parameter Plugin
CVE-2022-27203
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 March 2022
What is CVE-2022-27203?
The Jenkins Extended Choice Parameter Plugin allows users with Item/Configure permission to gain unauthorized access to the values stored in arbitrary JSON and Java properties files on the Jenkins controller. This vulnerability can expose sensitive configuration data and potentially lead to further exploitation or compromise of the Jenkins environment. Users are advised to update to the latest version of the plugin to mitigate risks associated with this issue.
Affected Version(s)
Jenkins Extended Choice Parameter Plugin <= 346.vd87693c5a_86c