CVE-2023-25765: Critical severity jenkins email extension template vulnerability
Published Feb 15, 2023
·Updated
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Affected Software
3 affected componentsFixes available
maven/org.jenkins-ci.plugins:email-ext<=2.93
2.94
Jenkins Email Extension Jenkins<=2.93
Jenkins Email Extension Jenkins<2.93.1
Event History
Feb 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-25765.
2
What is the severity of CVE-2023-25765?
The severity of CVE-2023-25765 is critical with a CVSS score of 9.9.
3
What is the affected software?
The affected software is Jenkins Email Extension Plugin versions 2.93 and earlier.
4
What can an attacker do with this vulnerability?
An attacker can bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
5
How can I fix CVE-2023-25765?
To fix CVE-2023-25765, update Jenkins Email Extension Plugin to version 2.93.1 or later.