PT-2022-27493 · Jenkins · Jenkins Ns-Nd Integration Performance Publisher Plugin+1
Daniel Beck
·
Published
2022-11-15
·
Updated
2023-11-01
·
CVE-2022-45391
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.143 and earlier
Description
The issue concerns the global and unconditional disabling of SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM. This affects the security of the system by not verifying the identity of the servers it connects to, potentially allowing man-in-the-middle attacks.
Recommendations
For versions 4.8.0.143 and earlier, update to version 4.8.0.146 or later, which no longer disables SSL/TLS certificate and hostname validation globally.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Ns-Nd Integration Performance Publisher Plugin