CVE-2017-2651 affects the Jenkins Mailer Plugin prior to version 1.20, allowing for information disclosure. The vulnerability arises when sending emails to dynamically generated lists based on changelogs, potentially exposing email addresses to unauthorized individuals, including those without Jenkins accounts or project involvement. This is a low-severity vulnerability with a CVSS score of 3.7, indicating a network attack vector with high attack complexity and a low impact on confidentiality. There is no evidence of active exploitation, no known public exploit code, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.20CPE matchmatch criteria | cpe:2.3:a:jenkins:mailer:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.