Jenkins Extended Choice Parameter Plugin Allows Unauthorized URL Connections
CVE-2022-27205
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 March 2022
What is CVE-2022-27205?
The Jenkins Extended Choice Parameter Plugin contains a vulnerability due to a missing permission check. This flaw permits attackers with Overall/Read permission to establish connections to maliciously specified URLs. This can potentially expose sensitive information or lead to further exploitation within the Jenkins environment. It's crucial for users of the affected versions to review their plugin configurations and apply necessary security measures to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Extended Choice Parameter Plugin <= 346.vd87693c5a_86c
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved