Количество 2
Количество 2
CVE-2017-1000397
около 8 лет назад
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
CVSS3: 5.9
EPSS: Низкий
GHSA-qhxw-54m9-6wwc
больше 3 лет назад
MitM on Jenkins Maven Plugin
CVSS3: 5.9
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-1000397 Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient. | CVSS3: 5.9 | 0% Низкий | около 8 лет назад | |
GHSA-qhxw-54m9-6wwc MitM on Jenkins Maven Plugin | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20