High severity7.5NVD Advisory· Published Aug 12, 2020· Updated Jun 17, 2026
CVE-2020-2232
CVE-2020-2232
Description
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:email-extMaven | >= 2.72, < 2.74 | 2.74 |
Affected products
4cpe:2.3:a:jenkins:email_extension:2.72:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:email_extension:2.72:*:*:*:*:jenkins:*:*
- cpe:2.3:a:jenkins:email_extension:2.73:*:*:*:*:jenkins:*:*
- Range: 2.72
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/08/12/4nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-5c4v-vh95-c67cghsaADVISORY
- jenkins.io/security/advisory/2020-08-12/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-2232ghsaADVISORY
- github.com/jenkinsci/email-ext-plugin/commit/b51497d044e36e950d698a79bb781ef4c83a251cghsaWEB
News mentions
1- Jenkins Security Advisory 2020-08-12Jenkins Security Advisories · Aug 12, 2020