Jenkins Mailer Plugin Vulnerability Exposure via Insufficient Permission Checks
CVE-2022-20614
4.3MEDIUM
What is CVE-2022-20614?
In the Jenkins Mailer Plugin, a missing permission check allows users with Overall/Read permissions to exploit the DNS functionalities of the Jenkins instance. This could lead to unauthorized hostname resolutions, potentially allowing attackers to manipulate DNS settings by specifying remote hostnames, posing significant risks to the integrity of Jenkins deployments.
Affected Version(s)
Jenkins Mailer Plugin <= 391.ve4a_38c1b_cf4b_
Jenkins Mailer Plugin 1.34.2