CVE-2023-32979

MEDIUM4.3EPSS 0.08%

Jenkins Email Extension Plugin missing permission check

Published: 5/16/2023Modified: 2/16/2024
Also known as:GHSA-6gp4-2f92-j2w5

Description

Jenkins Email Extension Plugin 2.96 and earlier does not perform a permission check in a method implementing form validation. This allows attackers with Overall/Read permission to check for the existence of files in the `email-templates/` directory in the Jenkins home directory on the controller file system. This form validation method requires the appropriate permission in Email Extension Plugin 2.96.1.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (2)