Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8x2-4gc8-9v3r

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Jenkins CollabNet Plugin man in the middle vulnerability

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to. CollabNet Plugin 2.0.5 and newer no longer does that. It instead requires users to opt in to disabling SSL/TLS certificate validation by setting the system property hudson.plugins.collabnet.CollabNetPlugin.skipSslValidation to true. This feature applies to connections by this plugin only.

Пакеты

Наименование

org.jenkins-ci.plugins:collabnet

maven
Затронутые версииВерсия исправления

<= 2.0.4

2.0.5

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
nvd
больше 7 лет назад

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-295