CVE-2020-2252
published 2020-09-16CVE-2020-2252: Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
PriorityP424medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.96%
57.5th percentile
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean_plugin | — | — |
| jenkins | clearcase_release_plugin | — | — |
| jenkins | complexity_scatter_plot_plugin | — | — |
| jenkins | computer_queue_plugin | — | — |
| jenkins | copy_data_to_workspace_plugin | — | — |
| jenkins | custom_job_icon_plugin | — | — |
| jenkins | description_column_plugin | — | — |
| jenkins | elastest_plugin | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | health_advisor_by_cloudbees_plugin | — | — |
| jenkins | jenkins_controller_in_perfecto_plugin | — | — |
| jenkins | locked_files_report_plugin | — | — |
| jenkins | mailer | <= 1.32 | — |
| jenkins | mailer_plugin | — | — |
| jenkins | mongodb_plugin | — | — |
| jenkins | pipeline_maven_integration_plugin | — | — |
| jenkins | radiator_view_plugin | — | — |
| jenkins | selection_tasks_plugin | — | — |
| jenkins | storable_configs_plugin | — | — |
| jenkins | validating_string_parameter_plugin | — | — |
| jenkins_project | jenkins_mailer_plugin | unspecified – 1.32 | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
ghsa·2022-05-24
CVE-2020-2252 [MEDIUM] CWE-295 Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
Jenkins Mailer Plugin prior to 1.32.1, 1.31.1, and 1.29.1 does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
Mailer Plugin 1.32.1, 1.31.1, and 1.29.1 validates the SMTP hostname when connecting via TLS by default. In Mailer Plugin 1.32 and earlier, administrators can set the Java system property mail.smtp.ssl.checkserveridentity to true on startup to enable this protection.
In case of problems, this protection can be disabled again by setting the Java system property mail.smtp.ssl.checkserveridentity to false on startup.
OSV
Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
osv·2022-05-24
CVE-2020-2252 [MEDIUM] Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
Jenkins Mailer Plugin prior to 1.32.1, 1.31.1, and 1.29.1 does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
Mailer Plugin 1.32.1, 1.31.1, and 1.29.1 validates the SMTP hostname when connecting via TLS by default. In Mailer Plugin 1.32 and earlier, administrators can set the Java system property mail.smtp.ssl.checkserveridentity to true on startup to enable this protection.
In case of problems, this protection can be disabled again by setting the Java system property mail.smtp.ssl.checkserveridentity to false on startup.
Red Hat
jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
vendor_redhat·2020-09-16·CVSS 4.8
CVE-2020-2252 [MEDIUM] CWE-297 jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
Jenkins
Jenkins Security Advisory 2020-09-16
vendor_jenkins·2020-09-16·CVSS 4.8
CVE-2020-2252 [MEDIUM] Jenkins Security Advisory 2020-09-16
Title: Jenkins Security Advisory 2020-09-16
Jenkins Security Advisory 2020-09-16
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
android-lint
Plugin
Blue Ocean
Plugin
chosen-views-tabbar
Plugin
ClearCase Release
Plugin
Computer Queue
Plugin
Copy data to workspace
Plugin
Coverage/Complexity Scat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2252 jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
bugzilla·2020-09-18·CVSS 4.8
CVE-2020-2252 [MEDIUM] CVE-2020-2252 jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
CVE-2020-2252 jenkins-2-plugins/mailer: Missing hostname validation in Mailer Plugin could result in MITM
Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
Discussion:
External References:
https://www.openwall.com/lists/oss-security/2020/09/16/3
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1813
---
In the jenkins-2-plugins package there is shipped the Mailer Plugin in version:
mailer-1.30 in OpenShift 4.5
mailer-1.32 in OpenShift 3.11
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.6
Via RHSA-2020:4297 https://access.redhat.com/errata/RHSA-2020:
Bugzilla
CVE-2020-1727 keycloak: missing input validation in IDP authorization URLs
bugzilla·2020-02-07·CVSS 6.4
CVE-2020-1727 [MEDIUM] CVE-2020-1727 keycloak: missing input validation in IDP authorization URLs
CVE-2020-1727 keycloak: missing input validation in IDP authorization URLs
During the assessment of the Admin Console application, it was found that almost every Authorization URL that points to an IDP server lacks on proper input validation. There is no need to allow a wide range of characters that a malicious user might be able to use to craft deep links that can introduce further attack scenarios on affected clients.
Reference:
https://issues.redhat.com/browse/KEYCLOAK-12192
Discussion:
Acknowledgments:
Name: Sebastian Moritz (Cure53)
---
This issue has been addressed in the following products:
Red Hat Runtimes Spring Boot 2.2.6
Via RHSA-2020:2252 https://access.redhat.com/errata/RHSA-2020:2252
---
This bug is now closed. Further updates for individual products will be reflec
Bugzilla
CVE-2020-1697 keycloak: stored XSS in client settings via application links
bugzilla·2020-01-16·CVSS 6.1
CVE-2020-1697 [MEDIUM] CVE-2020-1697 keycloak: stored XSS in client settings via application links
CVE-2020-1697 keycloak: stored XSS in client settings via application links
During the assessment of the Admin Console application, it was found that links to external applications, so called Application Links, does not get validated properly and therefore are prone to Stored XSS attacks. The affected parameter BaseURL within the Clients settings page from the admin console application accepts any characters and therefore it is possible to insert URLs with the javascript
https://issues.redhat.com/browse/KEYCLOAK-12459
Discussion:
Acknowledgments:
Name: Cure53 Berlin
---
This issue has been addressed in the following products:
Red Hat Runtimes Spring Boot 2.2.6
Via RHSA-2020:2252 https://access.redhat.com/errata/RHSA-2020:2252
---
This bug is now closed. Further updates for indiv
Bugzilla
CVE-2020-1698 keycloak: Password leak by logged exception in HttpMethod class
bugzilla·2020-01-13·CVSS 5.0
CVE-2020-1698 [MEDIUM] CVE-2020-1698 keycloak: Password leak by logged exception in HttpMethod class
CVE-2020-1698 keycloak: Password leak by logged exception in HttpMethod class
A flaw was found in keycloack. A logged exception in the HttpMethod class may leak password given as parameter.
References:
https://issues.redhat.com/browse/KEYCLOAK-12638
Discussion:
RHSSO 7.3.5 client adapters seem to be affected as they do ship keycloak-authz-client-4.8.15.Final-redhat-00001.jar
---
Marking RHDM/PAM as not affected as they do not ship this class :
https://github.com/keycloak/keycloak/blob/master/authz/client/src/main/java/org/keycloak/authorization/client/util/HttpMethod.java#L106
---
Acknowledgments:
Name: Tobias Friedrich
---
This issue has been addressed in the following products:
Red Hat Runtimes Spring Boot 2.2.6
Via RHSA-2020:2252 https://access.redhat.com/errata/RHSA-2020
2020-09-16
Published