Jenkins Mailer Plugin Vulnerability Exposure via Insufficient Permission Checks
CVE-2022-20614
4.3MEDIUM
Summary
In the Jenkins Mailer Plugin, a missing permission check allows users with Overall/Read permissions to exploit the DNS functionalities of the Jenkins instance. This could lead to unauthorized hostname resolutions, potentially allowing attackers to manipulate DNS settings by specifying remote hostnames, posing significant risks to the integrity of Jenkins deployments.
Affected Version(s)
Jenkins Mailer Plugin <= 391.ve4a_38c1b_cf4b_
Jenkins Mailer Plugin 1.34.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved