{"id":"CVE-2018-1000176","aliases":["GHSA-gwxm-wqpq-w539"],"url":"https://o3.security/vulnerability/CVE-2018-1000176","summary":"Jenkins Email Extension Plugin showed plain text SMTP password in configuration form field","details":"An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and ExtendedEmailPublisherDescriptor.java that allows attackers with control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured SMTP password.","published":"2018-05-08T15:29:00.410Z","modified":"2026-07-08T14:58:17.785459Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:email-ext","fixedVersion":"2.62"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2018-04-16/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000176"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2018-04-16"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:58:17.785459Z"}}