Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pavel Nakonechnyi

Pesquisador deNetcetera AG
#42318de 53,635
6.4CVSS total
Vulnerabilidades · 1
PT-2023-2501
6.4
2023-04-12
Jenkins · Jenkins Neuvector Vulnerability Scanner Plugin · CVE-2023-30517
**Name of the Vulnerable Software and Affected Versions** Jenkins NeuVector Vulnerability Scanner Plugin versions 1.22 and earlier **Description** The issue is related to improper SSL/TLS certificate authentication. It may allow a remote attacker to gain unauthorized access to protected information. The plugin unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server. **Recommendations** For Jenkins NeuVector Vulnerability Scanner Plugin versions 1.22 and earlier, update to a version that conditionally enables SSL/TLS certificate and hostname validation to prevent unauthorized access. As a temporary workaround, consider restricting access to the plugin until a patch is available.