Information Disclosure in Jenkins Mailer Plugin by CloudBees
CVE-2017-2651
3.7LOW
What is CVE-2017-2651?
The Jenkins Mailer Plugin prior to version 1.20 is susceptible to an information disclosure vulnerability that can arise when sending emails to a dynamically generated list of users based on changelogs. This flaw can unintentionally expose email communications to individuals who do not possess a user account in Jenkins, and in rare scenarios, it may even involve recipients not associated with the relevant project being built, due to linkage based on the local part of email addresses.
Affected Version(s)
jenkins-mailer-plugin 1.20