Back to overview

CVE-2023-25765

CRITICAL
9.9
CVSS 3.1
Description
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

Metadata

CVE ID
CVE-2023-25765
State
PUBLISHED
Assigner
jenkins
Reserved
2023-02-14 00:00 UTC
Published
2023-02-15 00:00 UTC
Last updated
2025-03-19 16:20 UTC
Primary CWE
CWE-693
CWE-693 Protection Mechanism Failure
Vendor / Product
Jenkins Project / Jenkins Email Extension Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Jenkins Project Jenkins Email Extension Plugin unspecified ≤ 2.93, 2.89.0.1
Weakness (CWE)
CWESourceDescription
CWE-693 adp CWE-693 Protection Mechanism Failure
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (2)
Back to overview