-
Bug
-
Resolution: Fixed
-
Critical
-
Jenkins 1.558, Jira-Plugin 1.39, Email-ext plugin 2.37.2.2
When sending an email, the jira-plugin provides an email adress from JIRA instead of the regular email adress combined from committer and the configured domain.
- if the username exists in jira, jenkins will use the email without any further notice that this happened
- the email adress is used even if the jira-account in question has no permission for the project being build (how should jenkins know?)
- the email adress is even used from disabled jira accounts (how should jenkins know?)
- this feature of the plugin can't be disabled
This can lead to emails being sent to wrong recipients.
- links to