CVE-2019-10382
published 2019-08-07CVE-2019-10382: Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
PriorityP431medium6.5CVSS 3.1
AVNACHPRNUINSUCHILAN
EPSS
0.84%
53.6th percentile
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | avatar_plugin | — | — |
| jenkins | build_pipeline_plugin | — | — |
| jenkins | codefresh_integration_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | file_system_scm_plugin | — | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | google_cloud_messaging_notification_plugin | — | — |
| jenkins | jclouds_plugin | — | — |
| jenkins | jenkins_instance_with_this_plugin | — | — |
| jenkins | mask_passwords_plugin | — | — |
| jenkins | pegdown_formatter_plugin | — | — |
| jenkins | relution_enterprise_appstore_publisher_plugin | — | — |
| jenkins | simple_travis_pipeline_runner_plugin | — | — |
| jenkins | testlink_plugin | — | — |
| jenkins | vmware_lab_manager_slaves | <= 0.2.8 | — |
| jenkins | vmware_lab_manager_slaves_plugin | — | — |
| jenkins | wall_display_master_project_plugin | — | — |
| jenkins | xl_testview_plugin | — | — |
| jenkins_project | jenkins_vmware_lab_manager_slaves_plugin | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
ghsa·2022-05-24
CVE-2019-10382 [MEDIUM] CWE-295 Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
VMware Lab Manager Slaves Plugin unconditionally disables SSL/TLS certificate validation for the entire Jenkins controller JVM.
As of publication of this advisory, there is no fix.
OSV
Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
osv·2022-05-24
CVE-2019-10382 [MEDIUM] Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
Jenkins VMware Lab Manager Slaves Plugin vulnerable to Improper Certificate Validation
VMware Lab Manager Slaves Plugin unconditionally disables SSL/TLS certificate validation for the entire Jenkins controller JVM.
As of publication of this advisory, there is no fix.
Jenkins
Jenkins Security Advisory 2019-08-07
vendor_jenkins·2019-08-07·CVSS 5.5
CVE-2019-10367 [MEDIUM] Jenkins Security Advisory 2019-08-07
Title: Jenkins Security Advisory 2019-08-07
Jenkins Security Advisory 2019-08-07
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Avatar
Plugin
Build Pipeline
Plugin
Codefresh Integration
Plugin
Configuration as Code
Plugin
eggplant-plugin
Plugin
File System SCM
Plugin
Google Cloud Messaging Noti
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-07
Published