[MAVEN:GHSA-6G57-H38C-Q52G] Cross-Site Request Forgery in Jenkins Mailer Plugin

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/mailer <= 1.20
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/mailer = 1.21
ID
MAVEN:GHSA-6G57-H38C-Q52G
Severity
high
URL
https://github.com/advisories/GHSA-6g57-h38c-q52g
Published
2022-05-14T01:29:12
(2 years ago)
Modified
2024-01-03T13:02:00
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/mailer org.jenkins-ci.plugins mailer <= 1.20
Fixed pkg:maven/org.jenkins-ci.plugins/mailer org.jenkins-ci.plugins mailer = 1.21
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...