Описание
Jenkins Cadence vManager Plugin disables SSL/TLS and hostname verification
Jenkins Cadence vManager Plugin prior to version 2.7.1 disables SSL/TLS and hostname verification globally for the Jenkins master JVM. This issue is patched in 2.7.1
Пакеты
Наименование
org.jenkins-ci.plugins:vmanager-plugin
maven
Затронутые версииВерсия исправления
< 2.7.1
2.7.1
Связанные уязвимости
CVSS3: 8.2
nvd
больше 6 лет назад
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.