CVE-2022-20614

Related Vulnerabilities: CVE-2022-20614  

A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Description

The MITRE CVE dictionary describes this issue as:

A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Additional Information

  • Bugzilla 2044497: CVE-2022-20614 jenkins-2-plugins/mailer: does not perform a permission check in a method implementing form validation
  • CWE-862: Missing Authorization
  • FAQ: Frequently asked questions about CVE-2022-20614