Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins mailer vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2022-20614
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and previous versions allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
Jenkins Mailer 391.ve4a 38c1b Cf4b
Jenkins Mailer
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
4.3
CVSSv2
CVE-2022-20613
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and previous versions allows malicious users to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
Jenkins Mailer 391.ve4a 38c1b Cf4b
Jenkins Mailer
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
5.8
CVSSv2
CVE-2020-2252
Jenkins Mailer Plugin 1.32 and previous versions does not perform hostname validation when connecting to the configured SMTP server.
Jenkins Mailer
4.3
CVSSv2
CVE-2017-2651
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in J...
Jenkins Mailer
6
CVSSv2
CVE-2018-8718
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.
Jenkins Mailer
1 EDB exploit
1 Github repository
4
CVSSv2
CVE-2017-1000395
Jenkins 2.73.1 and previous versions, 2.83 and previous versions provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses i...
Jenkins Jenkins
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started