Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server. This lack of validation could be abused using a man-in-the-middle attack to intercept these connections.
External References: https://www.openwall.com/lists/oss-security/2020/09/16/3 https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1813
In the jenkins-2-plugins package there is shipped the Mailer Plugin in version: mailer-1.30 in OpenShift 4.5 mailer-1.32 in OpenShift 3.11
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2020:4297 https://access.redhat.com/errata/RHSA-2020:4297
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-2252
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2020:5102 https://access.redhat.com/errata/RHSA-2020:5102