PT-2025-21241 · Jenkins · Jenkins Dingtalk Plugin+1

·

CVE-2025-47888

·

Published

2025-05-14

·

Updated

2025-06-12

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins DingTalk Plugin versions 2.7.3 and earlier
Description: The issue concerns the unconditional disabling of SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks. This affects the security of the connections, potentially exposing them to man-in-the-middle attacks or other security risks.
Recommendations: For Jenkins DingTalk Plugin versions 2.7.3 and earlier, consider disabling the plugin until a patched version is available that properly handles SSL/TLS certificate and hostname validation. As a temporary workaround, restrict access to the DingTalk webhooks to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47888
GHSA-CP9R-G575-XC5F

Affected Products

Jenkins
Jenkins Dingtalk Plugin