VYPR

mailer-plugin

by Jenkins Project

Source repositories

CVEs (2)

  • CVE-2017-2651Jul 27, 2018
    risk 0.00cvss epss 0.00

    jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in…

  • CVE-2018-8718Mar 27, 2018
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.