PT-2023-2575 · Jenkins · Jenkins Image Tag Parameter Plugin+1

Daniel Beck

·

Published

2023-04-12

·

Updated

2025-02-07

·

CVE-2023-30516

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Image Tag Parameter Plugin version 2.0
Description The Jenkins Image Tag Parameter Plugin improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries. This results in job configurations using Image Tag Parameters that were created before version 2.0 having SSL/TLS certificate validation disabled by default. The issue is related to incorrect authentication of SSL/TLS certificates, which could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For Jenkins Image Tag Parameter Plugin version 2.0, consider disabling the option to opt out of SSL/TLS certificate validation when connecting to Docker registries until a patch is available. Restrict access to job configurations using Image Tag Parameters that were created before version 2.0 to minimize the risk of exploitation. As a temporary workaround, enable SSL/TLS certificate validation for these configurations to prevent unauthorized access.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-02391
CVE-2023-30516
GHSA-38JC-2RWX-QGXR

Affected Products

Jenkins
Jenkins Image Tag Parameter Plugin