Jenkins Extensible Choice Parameter Plugin
cpe:2.3:a:jenkins:extended_choice_parameter:*:*:*:*:jenkins:*:*
- <= 239.v5f5c278708cf
A cross-site request forgery (CSRF) vulnerability exists in Jenkins Extensible Choice Parameter Plugin versions up to and including 239.v5f5c278708cf. This vulnerability allows attackers to execute sandboxed Groovy code by exploiting the plugin's failure to require POST requests for a specific HTTP endpoint.
Exploitation of this vulnerability could lead to unauthorized execution of sandboxed Groovy code on the Jenkins server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.