jenkinsci / jenkinsci/extended-choice-parameter-plugin

Security issue with the plugin

Open
#71 13 comments 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
72
Forks
99
PR merge metrics
No merged PRs in 30d

Description

### Jenkins and plugins versions report

Warning: This plugin version may not be safe to use. Please review the following security notices:
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617)
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2232)
[Arbitrary JSON and property file read vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1351)
[CSRF vulnerability and missing permission checks allow SSRF](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1350)

### What Operating System are you using (both controller, and any agents involved in the problem)?

Linux

### Reproduction steps

Warning: This plugin version may not be safe to use. Please review the following security notices:
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617)
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2232)
[Arbitrary JSON and property file read vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1351)
[CSRF vulnerability and missing permission checks allow SSRF](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1350)

### Expected Results

Warning: This plugin version may not be safe to use. Please review the following security notices:
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617)
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2232)
[Arbitrary JSON and property file read vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1351)
[CSRF vulnerability and missing permission checks allow SSRF](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1350)

### Actual Results

Warning: This plugin version may not be safe to use. Please review the following security notices:
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-04-12/#SECURITY-2617)
[Stored XSS vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2232)
[Arbitrary JSON and property file read vulnerability](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1351)
[CSRF vulnerability and missing permission checks allow SSRF](https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-1350)

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Review the four linked Jenkins security advisories and determine which plugin version and reporting path are implicated. The issue names no file, test, affected version, or distinct reproduction beyond the repeated warning, so those details must be established before work can be scoped. Done should be a confirmed, testable resolution for the identified security problem.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.