Jenkins Project Jenkins Mailer Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_mailer_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-20613MEDIUMCVSS 4.3≥ unspecified, ≤ 391.ve4a_38c1b_cf4b_2022-01-12
CVE-2022-20613 [MEDIUM] CWE-352 CVE-2022-20613: A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
cvelistv5nvd
CVE-2022-20614MEDIUMCVSS 4.3≥ unspecified, ≤ 391.ve4a_38c1b_cf4b_2022-01-12
CVE-2022-20614 [MEDIUM] CWE-862 CVE-2022-20614: A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attacker
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
cvelistv5nvd
CVE-2020-2252MEDIUMCVSS 4.8≥ unspecified, ≤ 1.322020-09-16
CVE-2020-2252 [MEDIUM] CWE-295 CVE-2020-2252: Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the c
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
cvelistv5nvd