CVE-2023-32979
16.05.2023, 16:15
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | email_extension | 𝑥 ≤ 2.96 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration