GHSA-6gp4-2f92-j2w5, CVE-2023-32979
maven/org.jenkins-ci.plugins/email-ext
Jenkins Email Extension Plugin missing permission check
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.
All versions before 2.96.1
Upgrade to version 2.96.1 or above.
2023-05-17
source |