Filtered by vendor Jenkins Project
Subscriptions
Filtered by product Jenkins Email Extension Plugin
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-48920 | 2 Jenkins, Jenkins Project | 2 Email Extension, Jenkins Email Extension Plugin | 2026-05-30 | 8.8 High |
| Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem. | ||||
Page 1 of 1.