CVE-2025-64133 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Jenkins Extensible Choice Parameter Plugin versions 239.v5f5c278708cf and earlier. This medium-severity vulnerability (CVSS 5.4) allows unauthenticated attackers to execute sandboxed Groovy code with user interaction. While the potential impact includes limited integrity and availability, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 239.v5f5c278708cfCPE matchmatch criteria | cpe:2.3:a:jenkins:extensible_choice_parameter:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.