In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
History

Wed, 19 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-03-19T16:20:52.614Z

Reserved: 2023-02-14T00:00:00.000Z

Link: CVE-2023-25765

cve-icon Vulnrichment

Updated: 2024-08-02T11:32:12.447Z

cve-icon NVD

Status : Modified

Published: 2023-02-15T14:15:13.700

Modified: 2025-03-19T17:15:38.733

Link: CVE-2023-25765

cve-icon Redhat

No data.