Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Caleb Tennis

Researcher fromCloudBees, Inc.
#26602of 53,632
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-7162
5.3
2018-08-06
Jenkins · Jenkins-Email-Ext · CVE-2017-2654
Name of the Vulnerable Software and Affected Versions: Jenkins-email-ext versions prior to 2.57.1 Description: The issue allows the Email Extension Plugin to send emails to a dynamically created list of users based on changelogs, such as authors of SCM changes since the last successful build. This could result in emails being sent to people who have no user account in Jenkins, and in rare cases, even people who were not involved in the project being built, due to mapping based on the local-part of email addresses. Recommendations: For versions prior to 2.57.1, update to version 2.57.1 or later to resolve the issue.
PT-2018-7159
4.3
2018-07-27
Jenkins · Jenkins Mailer Plugin · CVE-2017-2651
Name of the Vulnerable Software and Affected Versions: Jenkins Mailer Plugin versions prior to 1.20 Description: The issue allows for information disclosure when using the feature to send emails to a dynamically created list of users based on the changelogs. This could result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in the project, due to some mapping based on the local-part of email addresses. Recommendations: For Jenkins Mailer Plugin versions prior to 1.20, update to version 1.20 or later to resolve the issue.