Medium severity4.3NVD Advisory· Published Jan 12, 2022· Updated Jun 17, 2026
CVE-2022-20613
CVE-2022-20613
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:mailerMaven | >= 391.ve4a38c1bcf4b, < 408.vd726a | 408.vd726a |
org.jenkins-ci.plugins:mailerMaven | < 1.34.2 | 1.34.2 |
Affected products
5cpe:2.3:a:jenkins:mailer:*:*:*:*:*:jenkins:*:*+ 1 more
- cpe:2.3:a:jenkins:mailer:*:*:*:*:*:jenkins:*:*range: <1.34.2
- cpe:2.3:a:jenkins:mailer:391.ve4a_38c1b_cf4b_:-:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
- Range: unspecified
Patches
Vulnerability mechanics
References
6- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2022/01/12/6nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-85rq-hp8x-ghjqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-20613ghsaADVISORY
- www.jenkins.io/security/advisory/2022-01-12/nvdVendor AdvisoryWEB
- github.com/jenkinsci/mailer-plugin/commit/5e6051fae61a43564e22aa89cb24ed8a42a26052ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-01-12Jenkins Security Advisories · Jan 12, 2022