A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jenkins-ci.plugins:mailer(Maven) | 391.ve4a38c1bcf4b | 408.vd726a | N/A |
| org.jenkins-ci.plugins:mailer(Maven) | 0 | 1.34.2 | N/A |
CVSS Metrics