GHSA-c8qr-vfjf-62q3

Suggest an improvement
Source
https://github.com/advisories/GHSA-c8qr-vfjf-62q3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c8qr-vfjf-62q3/GHSA-c8qr-vfjf-62q3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c8qr-vfjf-62q3
Aliases
Published
2022-05-13T01:36:51Z
Modified
2024-02-18T05:29:29.902090Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin
Details

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.

Database specific
{
    "nvd_published_at": "2018-08-06T22:29:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-30T22:29:21Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:email-ext

Package

Name
org.jenkins-ci.plugins:email-ext
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/email-ext

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.57.1

Affected versions

2.*

2.11
2.12
2.13
2.14
2.14.1
2.15
2.16
2.18
2.19
2.20
2.21
2.22
2.24.1
2.25
2.27
2.27.1
2.28
2.29
2.30
2.30.1
2.30.2
2.31
2.32
2.33
2.34
2.35
2.35.1
2.36
2.37
2.37.1
2.37.2
2.37.2.2
2.38
2.38.1
2.38.2
2.39
2.39.3
2.40-beta
2.40
2.40.1
2.40.2
2.40.3
2.40.4
2.40.5
2.41
2.41.2
2.41.3
2.42
2.43
2.44
2.45
2.46
2.47
2.50
2.51
2.52
2.53
2.54
2.55
2.56
2.57