Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8qr-vfjf-62q3

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.

Пакеты

Наименование

org.jenkins-ci.plugins:email-ext

maven
Затронутые версииВерсия исправления

< 2.57.1

2.57.1

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
redhat
почти 9 лет назад

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.

CVSS3: 3.7
nvd
больше 7 лет назад

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.

EPSS

Процентиль: 18%
0.00058
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200