// For flags

CVE-2017-2651

 

Severity Score

3.7
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.

jenkins-mailer-plugin en versiones anteriores a la 1.20 es vulnerable a una divulgación de información mientras usa la característica para enviar correos electrónicos a una lista de usuarios creada dinámicamente basada en los changelogs. Esto podría en algunos casos resultar en el envío de correos electrónicos a personas que no tienen una cuenta de usuario en Jenkins, y en casos raros incluso a personas que no estaban involucradas en algún proyecto que se estuviera desarrollando, debido a algún mapeo basado en la parte local de las direcciones de correo electrónico.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2018-07-27 CVE Published
  • 2024-01-27 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Jenkins
Search vendor "Jenkins"
Mailer
Search vendor "Jenkins" for product "Mailer"
< 1.20
Search vendor "Jenkins" for product "Mailer" and version " < 1.20"
jenkins
Affected