PT-2023-3634 · Jenkins · Jenkins Checkmarx Plugin+1

Daniel Beck

·

Published

2023-06-14

·

Updated

2025-01-02

·

CVE-2023-35142

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Checkmarx Plugin versions 2022.4.3 and earlier
Description The issue is related to errors in SSL/TLS certificate validation. It may allow a remote attacker to perform a "man-in-the-middle" attack. The plugin disables SSL/TLS validation for connections to the Checkmarx server by default.
Recommendations For Jenkins Checkmarx Plugin versions 2022.4.3 and earlier, consider enabling SSL/TLS validation for connections to the Checkmarx server to prevent potential "man-in-the-middle" attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-03918
CVE-2023-35142
GHSA-RR3P-5FCF-V5M3

Affected Products

Jenkins
Jenkins Checkmarx Plugin