GHSA-6g57-h38c-q52g

Suggest an improvement
Source
https://github.com/advisories/GHSA-6g57-h38c-q52g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6g57-h38c-q52g/GHSA-6g57-h38c-q52g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6g57-h38c-q52g
Aliases
Published
2022-05-14T01:29:12Z
Modified
2024-02-18T05:24:26.531140Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Cross-Site Request Forgery in Jenkins Mailer Plugin
Details

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

References

Affected packages

Maven / org.jenkins-ci.plugins:mailer

Package

Name
org.jenkins-ci.plugins:mailer
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/mailer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21

Affected versions

1.*

1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12-beta-1
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.20

Database specific

{
    "last_known_affected_version_range": "<= 1.20"
}