Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1975 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2020/08/12/4 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-08-12 07:15
Updated : 2020-08-13 12:48
NVD link : CVE-2020-2232
Mitre link : CVE-2020-2232
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
jenkins
- email_extension