CVE-2020-2252: Jenkins Mailer

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.

Affected products

  • Jenkins Mailer: up to and including 1.32

Published 2020-09-16. Last modified 2026-06-17.