Description
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
Remediation
References
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1813
http://www.openwall.com/lists/oss-security/2020/09/16/3
Related Vulnerabilities
CVE-2021-46089 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2014-3625 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2018-11040 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2019-10373 Vulnerability in maven package org.jenkins-ci.plugins:build-pipeline-plugin
CVE-2019-10283 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration