In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2023-02-15T00:00:00

Updated: 2024-08-02T11:32:12.447Z

Reserved: 2023-02-14T00:00:00

Link: CVE-2023-25765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-02-15T14:15:13.700

Modified: 2023-11-03T02:00:58.373

Link: CVE-2023-25765

cve-icon Redhat

No data.