GHSA-fq9f-9wv9-rfmg
Dashboard / Vulnerabilities / GHSA-fq9f-9wv9-rfmg
Summary: Improper Certificate Validation in Jenkins
Details: Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000396, https://github.com/jenkinsci/jenkins/commit/fe77d1c3dbf91ddf2a9f8e5ed882611455ab00d0, https://github.com/jenkinsci/jenkins, https://jenkins.io/security/advisory/2017-10-11
Affected packages
Package
Name: org.jenkins-ci.main:jenkins-core
Purl: pkg:maven/org.jenkins-ci.main/jenkins-core
Affected ranges
Type: ECOSYSTEM
Events:
