CVE-2022-20613

CVSS v3.1 4.3 (Medium)
43% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.18 % (56th)
0.18% Progress
Affected Products 2
Advisories 2

A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2022-01-12 20:15:08
(2 years ago)
Updated Date
2023-11-22 21:32:32
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Mailer for Jenkins prior 1.34.2 version cpe:2.3:a:jenkins:mailer::*:*:*:*:jenkins < 1.34.2
  Jenkins Mailer 391.ve4a 38c1b Cf4b cpe:2.3:a:jenkins:mailer:391.ve4a_38c1b_cf4b_:-

Configuration #2

    CPE23 From Up To
  Oracle Communications Cloud Native Core Automated Test Suite 1.9.0 cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...