CVE-2017-2651
published 2018-07-27CVE-2017-2651: jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of…
PriorityP415low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
1.63%
73.5th percentile
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | all_versions_no_fix_for_this_plugin | — | — |
| jenkins | classpath_step_plugin | — | — |
| jenkins | distfork_plugin | — | — |
| jenkins | distributed_fork_plugin | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | jenkins-mailer-plugin | — | — |
| jenkins | jenkins_by_mailer_plugin | — | — |
| jenkins | mailer | < 1.20 | 1.20 |
| jenkins | pipeline_libraries_feature_no_fix_for_this_plugin | — | — |
| jenkins | ssh_build_agents_plugin | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
ghsa·2022-05-13
CVE-2017-2651 [LOW] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
osv·2022-05-13
CVE-2017-2651 [LOW] Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.
Jenkins
Jenkins Security Advisory 2017-03-20
vendor_jenkins·2017-03-20·CVSS 6.8
CVE-2017-2648 [MEDIUM] Jenkins Security Advisory 2017-03-20
Title: Jenkins Security Advisory 2017-03-20
Jenkins Security Advisory 2017-03-20
This advisory announces vulnerabilities in these Jenkins plugins:
Active Directory
DistFork
Email Extension (Email-ext)
Mailer
Pipeline: Classpath Step
SSH Build Agents
Description
SSH Build Agents Plugin did not verify host keys
SECURITY-161 / CVE-2017-2648
The SSH Build Agents Plugin did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
Active Directory Plugin did not verify certificate of AD server
SECURITY-251 / CVE-2017-2649
The Active Directory Plugin did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
Pipeline: Classpath Step plugin allowed Script Sec
Red Hat
jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
vendor_redhat·2017-03-20·CVSS 3.7
CVE-2017-2651 [LOW] CWE-200 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.
Package: jenkins-plugin-mailer (Red Hat OpenShift Enterprise 3) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7593 libtiff: tif_rawdata not properly initialized in tif_read.c
bugzilla·2017-04-11·CVSS 5.5
CVE-2017-7593 [MEDIUM] CVE-2017-7593 libtiff: tif_rawdata not properly initialized in tif_read.c
CVE-2017-7593 libtiff: tif_rawdata not properly initialized in tif_read.c
tif_read.c in LibTIFF does not ensure that tif_rawdata is properly initialized, which might allow attackers to crash the application, or possibly obtain sensitive information from process memory via a crafted image.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2651
Upstream patch:
https://github.com/vadz/libtiff/commit/d60332057b9575ada4f264489582b13e30137be1
Discussion:
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1438465]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1438466]
---
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1441273]
Bugzilla
CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin [fedora-all]
bugzilla·2017-03-21·CVSS 3.7
CVE-2017-2651 [LOW] CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin [fedora-all]
CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
bugzilla·2017-03-21·CVSS 3.7
CVE-2017-2651 [LOW] CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
CVE-2017-2651 jenkins-mailer-plugin: Emails were sent to addresses not associated with actual users of Jenkins by Mailer Plugin
The Mailer and Email Extension Plugins are able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build.
This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.
Affected versions: up to and including version 1.19
External Reference:
https://jenkins.io/security/advisory/2017-03-20/
Discussion:
Acknowledgments:
Name: the Jenkins project
Upstream: Caleb Tennis (CloudBees)
---
Create
2018-07-27
Published