PT-2018-7162 · Jenkins · Jenkins-Email-Ext+1

Caleb Tennis

·

Published

2018-08-06

·

Updated

2022-05-13

·

CVE-2017-2654

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins-email-ext versions prior to 2.57.1
Description: The issue allows the Email Extension Plugin to send emails to a dynamically created list of users based on changelogs, such as authors of SCM changes since the last successful build. This could result in emails being sent to people who have no user account in Jenkins, and in rare cases, even people who were not involved in the project being built, due to mapping based on the local-part of email addresses.
Recommendations: For versions prior to 2.57.1, update to version 2.57.1 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2654
GHSA-C8QR-VFJF-62Q3

Affected Products

Jenkins
Jenkins-Email-Ext