Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01ajlmLTV3bXAtN2Y4aM4AAiYo
Jenkins Cadence vManager Plugin disables SSL/TLS and hostname verification
Jenkins Cadence vManager Plugin prior to version 2.7.1 disables SSL/TLS and hostname verification globally for the Jenkins master JVM. This issue is patched in 2.7.1
Permalink: https://github.com/advisories/GHSA-5j9f-5wmp-7f8hJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01ajlmLTV3bXAtN2Y4aM4AAiYo
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 4 months ago
CVSS Score: 8.2
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Identifiers: GHSA-5j9f-5wmp-7f8h, CVE-2019-10446
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10446
- https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1615
- https://github.com/jenkinsci/vmanager-plugin/commit/639aa135ab57d9e23c5bedeb0a5e9518eb0f486e
- https://github.com/advisories/GHSA-5j9f-5wmp-7f8h
Affected Packages
maven:org.jenkins-ci.plugins:vmanager-plugin
Versions: < 2.7.1Fixed in: 2.7.1