Описание
Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation
Jenkins SiteMonitor Plugin unconditionally disables SSL/TLS certificate validation for the entire Jenkins controller JVM.
SiteMonitor Plugin no longer does that. Instead, it now has an opt-in option to ignore SSL/TLS errors for each site check individually.
Пакеты
Наименование
org.jvnet.hudson.plugins:sitemonitor
maven
Затронутые версииВерсия исправления
<= 0.5
0.6
Связанные уязвимости
CVSS3: 5.9
nvd
больше 6 лет назад
Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.