CVE-2022-20614
MEDIUMJenkins Mailer Plugin <391.ve4a_38c1f - Info Disclosure
Title source: llmDescription
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
References (3)
Core 3
Core References
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/01/12/6
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Scores
CVSS v3
4.3
EPSS
0.0010
EPSS Percentile
27.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-862
Status
published
Products (4)
jenkins/mailer
391.ve4a_38c1b_cf4b_
jenkins/mailer
< 1.34.2
oracle/communications_cloud_native_core_automated_test_suite
1.9.0
org.jenkins-ci.plugins/mailer
391.ve4a38c1bcf4b - 408.vd726aMaven
Published
Jan 12, 2022
Tracked Since
Feb 18, 2026