cbcvebase.
CVE-2020-2232
published 2020-08-12

CVE-2020-2232: Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.76%
51.1th percentile
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsemail_extension
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsflaky_test_handler_plugin
jenkinsids_in_pipeline_maven_integration_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinspipeline_maven_integration_plugin
jenkinsyet_another_build_visualizer_plugin
jenkins_projectjenkins_email_extension_plugin>= 2.72 < unspecifiedunspecified
jenkins_projectjenkins_email_extension_pluginunspecified – 2.73

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.