Jenkins Mailer 1.22 for Jenkins

CPE Details

Jenkins Mailer 1.22 for Jenkins
1.22
2019-04-16
11h41 +00:00
2019-04-16
11h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:mailer:1.22:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

mailer

Version

1.22

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-20613 2022-01-11 23h00 +00:00 A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
4.3
Medium
CVE-2022-20614 2022-01-11 23h00 +00:00 A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
4.3
Medium
CVE-2020-2252 2020-09-16 11h20 +00:00 Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
4.8
Medium