Jenkins Mailer 1.25 for Jenkins

CPE Details

Jenkins Mailer 1.25 for Jenkins
1.25
2020-09-21
14h35 +00:00
2020-09-21
14h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:mailer:1.25:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

mailer

Version

1.25

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-20613 2022-01-11 23h00 +00:00 A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
4.3
Medium
CVE-2022-20614 2022-01-11 23h00 +00:00 A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
4.3
Medium
CVE-2020-2252 2020-09-16 11h20 +00:00 Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
4.8
Medium