Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Jenkins Email Extension Plugin 安全漏洞
Vulnerability Description
Jenkins Email Extension Plugin是Jenkins开源的一个Jenkins邮件通知与构建消息扩展插件。 Jenkins Email Extension Plugin 1933.v45cec755423f及之前版本存在安全漏洞,该漏洞源于通过设置data-inline属性允许在邮件内容中内联base64图像,且未限制可内联的图像URL,可能导致攻击者控制邮件内容时指定file:URL读取Jenkins控制器文件系统中的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A