Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48920

Опубликовано: 27 мая 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as base64 in email content by setting the data-inline attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jenkins:email_extension:*:*:*:*:*:jenkins:*:*
Версия до 1925.v1598902b_58dd (включая)
cpe:2.3:a:jenkins:email_extension:1933.v45cec755423f:*:*:*:*:jenkins:*:*

EPSS

Процентиль: 22%
0.00299
Низкий

8.8 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 5.5
redhat
2 месяца назад

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.

CVSS3: 8.8
github
2 месяца назад

Jenkins Email Extension Plugin: Attackers able to control email content may specify `file:` URLs for images to read arbitrary files from Jenkins controller filesystem

EPSS

Процентиль: 22%
0.00299
Низкий

8.8 High

CVSS3

Дефекты

CWE-73