cbcvebase.
CVE-2020-2232
published 2020-08-12

CVE-2020-2232: Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsemail_extension
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsflaky_test_handler_plugin
jenkinsids_in_pipeline_maven_integration_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinspipeline_maven_integration_plugin
jenkinsyet_another_build_visualizer_plugin
jenkins_projectjenkins_email_extension_plugin>= 2.72 < unspecifiedunspecified
jenkins_projectjenkins_email_extension_pluginunspecified – 2.73