jenkins Vulnerabilities and Affected Products
Vulnerabilities associated with jenkins-mailer-plugin.
Products
Clear product- jenkins11 vulnerabilities
- Jenkins Code Dx Plugin5 vulnerabilities
- cas2 vulnerabilities
- Script Security Plugin2 vulnerabilities
- script_security2 vulnerabilities
- blazemeter_plugin1 vulnerability
- docker1 vulnerability
- git_server1 vulnerability
- github1 vulnerability
- gitlab_hook1 vulnerability
- groovy1 vulnerability
- icescrum1 vulnerability
- Jenkins Command Line Interface (CLI)1 vulnerability
- Jenkins Stapler Web Framework1 vulnerability
- Jenkins User Interface (UI)1 vulnerability
- jenkins-mailer-plugin1 vulnerability
- jenkins-ssh-slaves-plugin1 vulnerability
- jenkins-telegram-bot1 vulnerability
- Matrix Project Plugin1 vulnerability
- mattermost1 vulnerability
- openid1 vulnerability
- openshift-sync-plugin1 vulnerability
- pipeline\1 vulnerability
- shared_library_version_override1 vulnerability
- subversion_partial_release_manager1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-pluginjenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses. CWE-200Jul 27, 2018 | CVSS3.7v3.0 | EPSS1.63% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |