CVE-2022-27203
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller.
Affected products
Jenkins project · Jenkins Extended Choice Parameter Plugin