Description
An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and ExtendedEmailPublisherDescriptor.java that allows attackers with control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured SMTP password.
Remediation
References
https://jenkins.io/security/advisory/2018-04-16/
Related Vulnerabilities
CVE-2024-4367 Vulnerability in maven package org.webjars.bowergithub.mozilla:pdfjs-dist
CVE-2019-10348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2019-0231 Vulnerability in maven package org.apache.mina:mina-core
CVE-2023-6394 Vulnerability in maven package io.quarkus:quarkus-smallrye-graphql-client