CVE-2022-27204: CSRF
A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a86c and earlier allows attackers to connect to an attacker-specified URL.
Other sources
Extended Choice Parameter Plugin 346.vd87693c5a86c and earlier does not perform a permission check on form validation methods. This allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Additionally, these form validation methods do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27204?
The severity of CVE-2022-27204 is classified as a medium-risk vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2022-27204?
To fix CVE-2022-27204, upgrade the Jenkins Extended Choice Parameter Plugin to version 356.va_90a_94ca_62ec or later.
What versions of Jenkins Extended Choice Parameter Plugin are affected by CVE-2022-27204?
CVE-2022-27204 affects Jenkins Extended Choice Parameter Plugin version 346.vd87693c5a_86c and earlier.
What type of vulnerability is CVE-2022-27204?
CVE-2022-27204 is a cross-site request forgery (CSRF) vulnerability.
Can CVE-2022-27204 allow unauthorized access to my system?
Yes, CVE-2022-27204 can allow attackers to connect to an attacker-specified URL without proper permission checks.