Publish GHSA-3vwm-fc87-mq6h

This commit is contained in:
advisory-database[bot]
2023-10-30 21:13:53 +00:00
parent cecf98373e
commit 3e8465e35a
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vwm-fc87-mq6h",
"modified": "2022-12-15T19:45:46Z",
"modified": "2023-10-30T21:12:33Z",
"published": "2022-11-16T12:00:23Z",
"aliases": [
"CVE-2022-45391"
],
"summary": "SSL/TLS certificate validation globally and unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin",
"details": "NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.\n\nNS-ND Integration Performance Publisher Plugin 4.8.0.146 no longer disables SSL/TLS certificate and hostname validation globally.",
"summary": "Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally",
"details": "Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.\n\nNS-ND Integration Performance Publisher Plugin 4.8.0.146 no longer disables SSL/TLS certificate and hostname validation globally.",
"severity": [
{
"type": "CVSS_V3",
@@ -44,9 +44,17 @@
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/cavisson-ns-nd-integration-plugin"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2910%20%281%29"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2910%20(1)"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2022/11/15/4"
}
],
"database_specific": {