Описание
Jenkins Eggplant Runner Plugin protection mechanism disabled
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property jdk.http.auth.tunneling.disabledSchemes to an empty value as part of applying a proxy configuration.
This disables a protection mechanism of the Java runtime addressing CVE-2016-5597.
As of publication of this advisory, there is no fix.
Пакеты
Наименование
io.jenkins.plugins:eggplant-runner
maven
Затронутые версииВерсия исправления
<= 0.0.1.301.v963cffe8ddb
Отсутствует
Связанные уязвимости
CVSS3: 5.9
nvd
3 месяца назад
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.