CVE-2022-20613

MEDIUM

Jenkins Mailer Plugin <391.ve4a_38c1b_cf4b - CSRF

Title source: llm
STIX 2.1

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (4)
jenkins/mailer 391.ve4a_38c1b_cf4b_
jenkins/mailer < 1.34.2
oracle/communications_cloud_native_core_automated_test_suite 1.9.0
org.jenkins-ci.plugins/mailer 391.ve4a38c1bcf4b - 408.vd726aMaven
Published Jan 12, 2022
Tracked Since Feb 18, 2026