[MAVEN:GHSA-X95C-QRQR-2V27] CSRF vulnerability and missing permission checks in Extended Choice Parameter Plugin allow SSRF

Severity Moderate
Affected Packages 1
CVEs 1

Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not perform a permission check on form validation methods. This allows attackers with Overall/Read permission to connect to an attacker-specified URL.

Additionally, these form validation methods do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/extended-choice-parameter <= 346.vd87693c5a
ID
MAVEN:GHSA-X95C-QRQR-2V27
Severity
moderate
URL
https://github.com/advisories/GHSA-x95c-qrqr-2v27
Published
2022-03-16T00:00:43
(2 years ago)
Modified
2023-02-02T05:04:51
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/extended-choice-parameter org.jenkins-ci.plugins extended-choice-parameter <= 346.vd87693c5a
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...