QID 997273
Date Published: 2024-02-20
QID 997273: Java (Maven) Security Update for org.jenkins-ci.plugins:email-ext (GHSA-gwxm-wqpq-w539)
An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and ExtendedEmailPublisherDescriptor.java that allows attackers with control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured SMTP password.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gwxm-wqpq-w539 for updates and patch information.
Vendor References
- GHSA-gwxm-wqpq-w539 -
github.com/advisories/GHSA-gwxm-wqpq-w539
CVEs related to QID 997273
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gwxm-wqpq-w539 | org.jenkins-ci.plugins:email-ext |
|