Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-25765
HistoryFeb 15, 2023 - 2:15 p.m.

Code injection

2023-02-1514:15:00
PRIOn knowledge base
www.prio-n.com
6
jenkins
email extension plugin
code injection
script security
sandbox protection
arbitrary code
jenkins controller jvm

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.2%

In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CPENameOperatorVersion
email_extensionlt2.93.1

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.2%

Related for PRION:CVE-2023-25765