Description
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.
References
http://www.openwall.com/lists/oss-security/2022/11/15/4
Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/11/15/4
Mailing ListThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-15T19:15:11.193Z
3 years agoLast modified
2025-04-30T14:15:22.393Z
11 months ago