CVE-2022-45391
7.5HIGHJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
Опубликовано: 11/15/2022Обновлено: 4/30/2025
Описание
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
ИИ-АнализНа базе ИИ
Затронутые продукты
jenkinsns-nd_integration_performance_publisher
Ссылки
- http://www.openwall.com/lists/oss-security/2022/11/15/4Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2910%20%281%29Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/11/15/4Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2910%20%281%29Vendor Advisory