CVE-2020-2232: Jenkins Email Extension

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.

Affected products

  • Jenkins Email Extension: version 2.72 only; version 2.73 only

Published 2020-08-12. Last modified 2026-06-17.