PT-2018-7159 · Jenkins · Jenkins Mailer Plugin+1

Caleb Tennis

·

Publicado

2018-07-27

·

Atualizado

2022-05-13

·

CVE-2017-2651

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins Mailer Plugin versions prior to 1.20
Description: The issue allows for information disclosure when using the feature to send emails to a dynamically created list of users based on the changelogs. This could result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in the project, due to some mapping based on the local-part of email addresses.
Recommendations: For Jenkins Mailer Plugin versions prior to 1.20, update to version 1.20 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2651
GHSA-9V72-P5P3-9W65

Produtos afetados

Jenkins
Jenkins Mailer Plugin