PT-2019-11838 · Hewlett Packard+1 · Hp Alm+2
Viktor Gazdag
·
Published
2019-10-16
·
Updated
2023-10-25
·
CVE-2019-10444
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Bumblebee HP ALM Plugin versions 4.1.3 and earlier
Description
The issue concerns the Jenkins Bumblebee HP ALM Plugin unconditionally disabling SSL/TLS and hostname verification for connections to HP ALM. This means that the plugin did not validate the identity of the HP ALM server it was connecting to, which could allow for man-in-the-middle attacks. The plugin now allows users to opt out of certificate validation, addressing the previous unconditional disabling of SSL/TLS certificate validation.
Recommendations
For Jenkins Bumblebee HP ALM Plugin versions 4.1.3 and earlier, update to a version that allows users to opt out of certificate validation to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the HP ALM service to minimize the risk of unauthorized connections.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Alm
Jenkins
Jenkins Bumblebee Hp Alm Plugin