Lucene search

K
osvGoogleOSV:GHSA-XMQV-PFW7-QMJ7
HistoryMay 24, 2022 - 4:47 p.m.

Jenkins ElectricFlow Plugin globally and unconditionally disabled SSL/TLS certificate validation

2022-05-2416:47:43
Google
osv.dev
8
jenkins electricflow plugin
ssl/tls certificate validation
cloudbees cd plugin
entire jenkins controller jvm
opt-in option
specific connection
security advisory

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

70.5%

CloudBees CD Plugin unconditionally disabled SSL/TLS certificate validation for the entire Jenkins controller JVM during the deployment/publication of an application.

CloudBees CD Plugin no longer does that. Instead, the existing opt-in option to ignore SSL/TLS errors is used during deployment for the specific connection.

This issue was caused by an incomplete fix for SECURITY-937.

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

70.5%

Related for OSV:GHSA-XMQV-PFW7-QMJ7